Back to skill

Security audit

Alibaba Cloud Platform DevOps

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Alibaba Cloud DevOps helper whose credential use, network calls, and local outputs fit its stated purpose.

Install only if you intend to work with Alibaba Cloud DevOps resources. Use least-privilege or read-only credentials where possible, run the SDK in a virtual environment, keep generated output private and out of source control, and require explicit approval plus a rollback plan before any create, update, run, or stop operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs use of environment credentials, network access to Alibaba Cloud/OpenAPI endpoints, and writing outputs to local files, yet it does not declare any permissions. This creates a trust and review gap: an operator or orchestration layer may treat the skill as lower risk than it actually is, even though it can access secrets, exfiltrate data over the network, and persist potentially sensitive cloud metadata to disk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.