Back to skill

Security audit

Alibaba Cloud Data Lake DLF

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Alibaba Cloud Data Lake Formation helper whose credential use, metadata lookup, and local outputs fit its stated purpose.

Install this only if you want an agent to help manage Alibaba Cloud Data Lake Formation. Use least-privilege Alibaba Cloud credentials, verify the active account, region, and resource IDs before each operation, require explicit approval for mutating API calls, and review files written under output/aliyun-dlf-manage/ because they may contain operational metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill uses sensitive capabilities (environment credential access, network calls, and local file writes) but does not declare permissions or boundaries. This reduces transparency and reviewability, making it easier for the skill to access cloud credentials and exfiltrate or persist data without explicit operator awareness.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill description focuses on Data Lake management, but the documented behavior also includes fetching OpenAPI metadata from remote endpoints, enumerating APIs, and writing artifacts locally. Undisclosed secondary behaviors increase attack surface and can surprise users, especially when cloud credentials and network access are involved.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.