Back to skill

Security audit

Alibaba Cloud Network DNS Cli

Security checks for vulnerabilities and agentic risk

Overview

This Alibaba Cloud DNS skill is purpose-aligned, but it asks users to install an unverified mutable CLI binary and configure cloud credentials before running high-impact DNS changes.

Review before installing. Use least-privilege Alibaba Cloud credentials limited to the intended DNS zone, prefer temporary environment variables or a dedicated temporary profile, verify the aliyun-cli download through a pinned version and checksum if possible, and require explicit confirmation plus rollback notes before any AddDomainRecord or update operation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:22
Finding

Unpinned Remote Executable Download Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22-26
Vulnerability Type: Mutable remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsSL https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz -o /tmp/aliyun-cli.tgz
mkdir -p ~/.local/bin
 tar -xzf /tmp/aliyun-cli.tgz -C /tmp
mv /tmp/aliyun ~/.local/bin/aliyun
chmod +x ~/.local/bin/aliyun

Technical Analysis

The installation workflow downloads an archive identified by the mutable latest path and installs the contained executable without verifying a cryptographic checksum or vendor signature. Consequently, the effective code installed by the Skill can change after the Skill itself has been reviewed.

Although the archive is retrieved over HTTPS from an official Alibaba Cloud domain, transport encryption alone does not protect against compromise of the origin server, CDN, release pipeline, DNS infrastructure, or vendor account. It also does not ensure that a later release has the same reviewed behavior.

The downloaded binary is subsequently intended to receive Alibaba Cloud credentials and perform DNS-management operations. A substituted executable would therefore run with the local privileges of the Agent user and could access credentials supplied to the CLI.

Attack Path

  1. An attacker compromises the download origin, CDN, release pipeline, or another component capable of changing the archive served by the mutable URL.
  2. The attacker replaces the archive with one containing a malicious aliyun executable.
  3. A user or Agent follows the documented installation workflow.
  4. The archive is accepted without a checksum or signature check, extracted into /tmp, and moved to ~/.local/bin/aliyun.
  5. The installed binary is executed during credential configuration or DNS operations.
  6. The malicious executable runs with the Agent user's privileges and can read supplied credentials, alter ...[truncated 768 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable latest URL with a fixed, explicitly reviewed CLI version.
  2. Obtain the expected SHA-256 digest through a trusted, versioned release channel and verify it before extraction:
    bash
    printf '%s  %s\n' "$EXPECTED_SHA256" /tmp/aliyun-cli.tgz | sha256sum --check -
    
  3. Verify a vendor-provided cryptographic signature in addition to the checksum when signed release artifacts are available.
  4. Abort installation immediately if integrity or signature verification fails.
  5. Download into a newly created private temporary directory, rather than using predictable shared /tmp paths, and remove the directory after installation.
  6. Inspect the archive contents before extraction and reject absolute paths, parent-directory traversal entries, unexpected files, and symbolic-link attacks.
  7. Document the pinned version and digest in the Skill so reviewers can verify exactly which executable will be installed.
  8. Continue using least-privilege Alibaba Cloud credentials so compromise of the CLI does not expose permissions beyond the required DNS operations.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill installs a binary into ~/.local/bin and configures credentials under the default profile, creating persistent changes to the host environment and potentially leaving sensitive cloud access usable beyond the current task. This increases risk if the environment is shared, long-lived, or later compromised, because both tooling and credentialed configuration remain available after execution.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

bash
curl -fsSL https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz -o /tmp/aliyun-cli.tgz
mkdir -p ~/.local/bin
 tar -xzf /tmp/aliyun-cli.tgz -C /tmp
mv /tmp/aliyun ~/.local/bin/aliyun
chmod +x ~/.local/bin/aliyun

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill provides direct commands to add DNS records, which are mutating operations that can affect production traffic, service routing, and domain validation, but it does not place a prominent user-facing warning immediately alongside the command about outage or hijack risk. In a DNS-management skill, mutation is expected, yet the lack of an explicit safety warning and change-control guidance increases the chance of accidental harmful changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and surrounding natural-language content are entirely in Chinese, which can impose a language requirement on users without explicit opt-in. The policy allows locale constraints when they are clearly documented and justified, but this file does not state that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.