Back to skill

Security audit

Alibaba Cloud AI Translation Anytrans

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Alibaba Cloud AnyTrans administration helper, with expected cloud API, credential, and local output behavior for that purpose.

Install this only if you intend to administer Alibaba Cloud AnyTrans resources. Use least-privilege credentials, review any create/update/modify/set action before it runs, and avoid saving access keys or secret-bearing command output in the evidence directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'timeout' from os.getenv (line 34, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 23)May include surrounding context.

python
def fetch_json(url: str, timeout: int) -> dict:
    req = urllib.request.Request(url, headers={"User-Agent": "codex-skill"})
    with urllib.request.urlopen(req, timeout=timeout) as resp:
        return json.loads(resp.read().decode("utf-8"))

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents the skill as managing TongyiTranslate resources and tasks, but the documented executable path focuses on OpenAPI metadata discovery and writing inventory artifacts locally. This mismatch can cause an agent or user to invoke the skill under false assumptions, leading to unintended network activity, confusing outputs, and misuse in contexts where only resource-management behavior was expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares operational behavior that can access environment credentials, write files, and make network calls, but it does not constrain or disclose tool scope via explicit permissions or allowed-tools. In an agent setting, this increases the chance of over-broad execution and unintended access to sensitive credentials or external endpoints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger description is broad enough to match generic translation-related requests, even though this skill is specifically for Alibaba Cloud AnyTrans administration. Over-broad matching can route unrelated user prompts into a cloud-management skill that has credentialed network and file-write capabilities, increasing the chance of inappropriate invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises create/update/modify operations against Alibaba Cloud resources without prominently warning about live side effects, state changes, or potential cost implications. In an autonomous or semi-autonomous agent workflow, this can lead to accidental mutation of production resources when a user expects read-only assistance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 3)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 4)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 5)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 39)May include surrounding context.

python
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs use of Alibaba Cloud access keys from environment variables or shared credentials files but does not warn against exposing those secrets in logs, saved artifacts, or command output. Because the skill also writes evidence to local output directories, there is a realistic risk of accidental credential leakage during troubleshooting or artifact collection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.