Back to skill

Security audit

Alibaba Cloud Backup BDRC

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alibaba Cloud BDRC helper that can use cloud credentials, call Alibaba Cloud APIs, and write local API inventory artifacts when directed.

Install only if you want an agent to help operate Alibaba Cloud BDRC. Use a RAM user or temporary role with the minimum needed permissions, confirm the account, region, resource IDs, and whether each action is read-only or mutating before running it, and review files under output/alicloud-backup-bdrc/ before sharing or committing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs use of environment credentials, local file writes, and network access but does not declare permissions to match those capabilities. This creates a transparency and governance gap: users or policy engines may approve the skill without understanding that it can access cloud credentials, contact external endpoints, and persist data locally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The skill is presented as a full BDRC management tool, but the described executable path centers on metadata discovery and artifact generation rather than actual backup/disaster-recovery operations. This mismatch can mislead operators about what the skill will do, causing inappropriate trust, execution in sensitive environments, or accidental exposure of credentials and internal API inventory data during what appears to be routine cloud administration.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.