Back to skill

Security audit

Alibaba Cloud AI Contactcenter AI

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alibaba Cloud CLI guidance skill, but it can help run credentialed cloud commands, so users should approve changes before execution.

Install only if you intend to let an agent help with Alibaba Cloud CLI work. Use least-privilege RAM credentials, prefer OAuth or temporary credentials where possible, review every command before it runs, and require explicit confirmation for any command that creates, changes, deletes, scales, or may incur charges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs use of environment credentials, network access to Alibaba/OpenAPI endpoints, and local file writes, but does not declare those capabilities as permissions. This creates a trust and review gap: an operator may approve the skill without realizing it can access cloud credentials, contact external services, and persist artifacts locally.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow explicitly encourages Create/Update/Modify/Set operations and lifecycle changes, but does not require a clear user confirmation or warning before mutating cloud resources. In a cloud-management skill, that omission increases the risk of accidental configuration drift, service disruption, or unintended charges if the agent proceeds with destructive or state-changing actions.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.