Back to skill

Security audit

Alibaba Cloud Compute FC Serverless Devs

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Alibaba Cloud deployment guide, but it repeatedly recommends unnecessary sudo use, unpinned remote CLI execution, and risky credential handling for cloud operations.

Install only if you are comfortable reviewing and modifying the commands first: avoid sudo for Serverless Devs operations, pin or vet the CLI version, use least-privilege short-lived Alibaba Cloud credentials where possible, avoid putting secrets in command lines or logs, and require explicit confirmation before deploy or remove.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Third-Party Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27-37 and 140
Vulnerability Type: Unpinned npm dependency and automatic remote package execution
Risk Level: Medium

Vulnerable Code

bash
# Lines 27-37
Global install (requires sudo):

sudo npm install @serverless-devs/s -g
sudo s -v

No-sudo alternative (recommended in restricted environments):

npx -y @serverless-devs/s -v
bash
# Line 140
printf 'y\n' | npx -y @serverless-devs/s deploy

Technical Analysis

The commands install or execute @serverless-devs/s without specifying an exact version or verifying an integrity digest. In particular, npx -y can retrieve the current registry version and execute it without an interactive package-installation confirmation.

Consequently, the code executed at deployment time can differ from the package version available when the Skill was reviewed. Although the package name is consistent with the documented workflow and no malicious dependency is embedded in the project itself, this creates supply-chain exposure. A compromised package release, package maintainer account, registry response, or transitive dependency could introduce arbitrary code.

The global installation command is additionally run through sudo, which increases the consequences of dependency compromise. The separate excessive-privilege issue is documented in another finding.

Attack Path

  1. An attacker compromises the package publisher, npm package, registry delivery path, or a transitive dependency.
  2. The attacker publishes malicious code under a version selected by the unpinned package reference.
  3. A user or Agent follows the Skill and runs either npm install @serverless-devs/s -g or npx -y @serverless-devs/s ....
  4. npm downloads the changed package content because no exact reviewed version or integrity value is required.
  5. Package installation hooks or runtime code execute on the local host.
  6. The malicious code accesses local files, environme ...[truncated 499 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin @serverless-devs/s to a specifically reviewed version rather than resolving the latest available release.
  • Use a committed lockfile where applicable and verify package integrity against a trusted digest.
  • Do not use npx -y for deployment because it combines unattended download and execution.
  • Install dependencies in advance from a trusted registry and execute the verified local binary.
  • Review package provenance, lifecycle scripts, and transitive dependencies before use.
  • Avoid running npm package installation or package-controlled commands through sudo.
  • Establish a controlled upgrade process in which new versions are reviewed and tested before changing the pin.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:27
Finding

Cloud CLI Commands Are Unnecessarily Executed with Root Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27-31, 40-43, 74-77, and 83-88
Vulnerability Type: Violation of operating-system least privilege
Risk Level: High

Vulnerable Code

bash
# Lines 27-31
Global install (requires sudo):

sudo npm install @serverless-devs/s -g
sudo s -v
bash
# Lines 40-43
## Configure Credentials (guided)

sudo s config add
bash
# Lines 74-77
## Initialize Example (Python)

sudo s init start-fc3-python
bash
# Lines 83-88
## Deploy, Invoke, and Remove

sudo s deploy
sudo s invoke -e "test"
sudo s remove

Technical Analysis

Credential configuration, template initialization, cloud deployment, function invocation, and cloud-resource removal do not ordinarily require operating-system root privileges. Running these operations through sudo gives the Serverless Devs CLI—and any package code, lifecycle hook, plugin, component, or downloaded project template it executes—permissions beyond those needed for the declared Function Compute task.

This breaks the local least-privilege boundary. It may also create root-owned credential or project files, causing users to continue using sudo for subsequent operations and expanding the exposure window.

The project does not contain an embedded privilege-escalation exploit, and the commands visibly request sudo; nevertheless, the documented workflow unnecessarily elevates externally supplied tooling.

Attack Path

  1. An attacker compromises the Serverless Devs package, one of its dependencies or components, or a template loaded during initialization.
  2. The user follows the documented workflow and invokes the affected operation with sudo.
  3. The compromised code runs in the elevated CLI process.
  4. It modifies root-owned files, installs additional software, reads protected data, changes system configuration, or establishes control over the host.
  5. If cloud credentials are available to the process, the same code can also perform ope ...[truncated 503 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove sudo from all s config, s init, s deploy, s invoke, and s remove commands.
  • Install and execute Serverless Devs as a dedicated unprivileged user.
  • If a global npm installation is undesirable without elevation, use a user-local npm prefix, a project-local dependency, or an approved package-manager configuration.
  • Ensure credential and project files are owned by the intended unprivileged user and have restrictive permissions.
  • Run third-party templates and components in a sandbox or isolated development environment where feasible.
  • Document that operating-system elevation is neither required nor permitted for ordinary cloud operations.
  • Retain least-privilege Alibaba Cloud policies independently of local operating-system privilege controls.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Alibaba Cloud Credentials Can Be Exposed Through Command Arguments and Environment Variables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49-69
Vulnerability Type: Insecure handling of sensitive credentials
Risk Level: Medium

Vulnerable Code

bash
# Lines 49-53
## Configure Credentials (command)

Use CLI args to configure credential alias in one command (non-interactive):

s config add -a default --AccessKeyID <AK> --AccessKeySecret <SK> -f
bash
# Lines 55-59
If using environment variables, inject them into the command (example):

s config add -a default -kl AccessKeyID,AccessKeySecret -il ${ALIBABA_CLOUD_ACCESS_KEY_ID},${ALIBABA_CLOUD_ACCESS_KEY_SECRET} -f
bash
# Lines 61-69
Or use Serverless Devs convention JSON environment variable (example):

export default_serverless_devs_key='{\"AccountID\":\"<AccountID>\",\"AccessKeyID\":\"<AK>\",\"AccessKeySecret\":\"<SK>\"}'

Reference in `s.yaml`:

access: default_serverless_devs_key

Technical Analysis

The first command places the access-key ID and secret directly in the process argument list. Depending on the operating system and execution environment, command arguments may be exposed through process inspection, shell history, terminal transcripts, audit records, CI logs, or Agent tool logs.

The second command expands environment variables into command-line arguments before execution, so using environment variables at the shell level does not prevent the resulting values from entering the process argument list.

The exported JSON alternative retains long-lived credentials in the environment inherited by child processes. Any untrusted dependency, CLI component, template hook, or other child process can read those values. This is especially concerning because SKILL.md, lines 168-173, instructs operators to save command output and evidence; without an explicit redaction policy, sensitive values could be retained in generated artifacts.

No real credentials are hardcoded in the repository—the displayed values are placehol ...[truncated 1307 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pass access-key secrets as command-line arguments.
  • Prefer a secure interactive prompt that does not echo or persist secret input.
  • Where supported, use a protected credential file or operating-system secret store with permissions restricted to the intended user.
  • Prefer short-lived credentials obtained through role assumption or workload identity over long-lived access keys.
  • Limit credentials to the minimum Alibaba Cloud actions and resources required for the task.
  • Explicitly prohibit recording secrets in command output, validation artifacts, screenshots, or evidence files.
  • Add mandatory redaction for access-key IDs, secrets, tokens, and credential JSON before evidence is saved.
  • Clear sensitive environment variables promptly after use and prevent untrusted child processes from inheriting them.
  • Rotate any credential suspected of appearing in shell history, process telemetry, CI output, or retained logs.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:140
Finding

Automatic Confirmation Bypasses the Deployment Approval Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 140
Vulnerability Type: Unattended confirmation of a mutating cloud operation
Risk Level: Low

Vulnerable Code

bash
printf 'y\n' | npx -y @serverless-devs/s deploy

Technical Analysis

The command pipes an affirmative response into the deployment process, bypassing an interactive confirmation prompt. Deployment is a mutating operation that may create or change externally accessible and billable cloud resources.

This behavior conflicts with the workflow requirements at SKILL.md, lines 181-184, which state that user intent and mutation status should be confirmed before execution and that the target operation should use explicit, bounded parameters. A generic pre-supplied y does not allow the user to inspect and approve the final deployment plan, resource scope, region, or cost implications.

The command does not independently prove that every Serverless Devs invocation will prompt for approval, but it is expressly designed to answer an expected prompt automatically and therefore removes a safety boundary.

Attack Path

  1. An Agent prepares or enters a project containing an incorrect region, domain route, function name, or other deployment property.
  2. The Agent runs the documented command.
  3. npx starts the deployment process and printf automatically supplies an affirmative answer to its prompt.
  4. The deployment proceeds without the user reviewing and approving the final action.
  5. Unintended resources or routing changes are created, and associated cloud usage may incur cost.

Impact Assessment

The operation can create or alter Alibaba Cloud resources available to the configured identity. Potential effects include unintended Function Compute deployment, incorrect custom-domain routing, public exposure of a function, service disruption, or unexpected charges. It does not grant permissions beyond the configured cloud credentials, but it increases the likelihood t ...[truncated 71 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the printf 'y\n' | automatic-confirmation pipeline.
  • Present the final deployment plan, target account, region, resource identifiers, public exposure, and expected mutations to the user.
  • Obtain explicit approval immediately before executing the deployment.
  • Use non-interactive deployment only when the CLI supports a documented, auditable flag and the user has already approved the exact plan.
  • Add validation that the selected region, domain, function, qualifier, and route match the user's stated intent.
  • Use dry-run or preview functionality where available and retain the sanitized plan as evidence.
  • Require separate explicit confirmation for destructive operations such as remove.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill recommends sudo npm install ... -g, which combines elevated privileges with installation of a package from a public registry. If the package or one of its dependencies is compromised, arbitrary code would run as root, significantly increasing host impact.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Global install (requires sudo):

bash
sudo npm install @serverless-devs/s -g
sudo s -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
76% confidence
Finding

sudo s -v runs a version check as root, which is unnecessary and normalizes privileged execution of the CLI. While lower risk than installation, it encourages a habit of invoking cloud tooling with elevated permissions, expanding the blast radius if later commands or plugins are compromised.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

bash
sudo npm install @serverless-devs/s -g
sudo s -v

No-sudo alternative (recommended in restricted environments):

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

sudo s -v

text

No-sudo alternative (recommended in restricted environments):

```bash
npx -y @serverless-devs/s -v

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx -y @serverless-devs/s without pinning a version causes execution of whatever package version is current at runtime. In a skill that instructs users to configure cloud credentials and deploy resources, this creates a supply-chain risk where a compromised or malicious package update could execute arbitrary code and access Alibaba Cloud secrets.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

Running sudo s config add elevates a credential-handling command unnecessarily, potentially storing or exposing cloud credentials in a root-owned context and increasing harm if the CLI is malicious or compromised. Because the command collects Alibaba Cloud access keys, the combination of privilege and secret handling is especially risky.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Configure Credentials (guided)

bash
sudo s config add

Choose Alibaba Cloud (alibaba), provide AccountID, AccessKeyID, AccessKeySecret, and set alias.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

Using sudo s init causes generated project files and directories to be created with root ownership and executes the initialization logic with elevated privileges. This can lead to unnecessary system-level impact if templates or plugins execute code during initialization.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Initialize Example (Python)

bash
sudo s init start-fc3-python
cd start-fc3-python

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents s remove alongside deploy and invoke commands without an explicit warning that it deletes deployed resources. In an operational skill for cloud infrastructure, this increases the risk of accidental destructive actions, especially if followed verbatim by users or automation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

sudo s deploy executes a cloud deployment action with root privileges, unnecessarily coupling infrastructure operations with full host privilege. If the CLI, a plugin, or a dependency is compromised, the attacker could affect both cloud resources and the local machine at the highest privilege level.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

Deploy, Invoke, and Remove

bash
sudo s deploy
sudo s invoke -e "test"
sudo s remove

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

sudo s invoke -e "test" runs a function invocation command as root even though invocation does not normally require local administrative rights. This expands local risk unnecessarily and may expose environment data or CLI behavior under elevated privilege.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
sudo s deploy
sudo s invoke -e "test"
sudo s remove

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

sudo s remove combines a destructive cloud action with unnecessary local root privilege, increasing both the likelihood and consequence of mistakes or compromise. In this skill context, removal can delete deployed resources while any compromised CLI logic would also run with full system privileges.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

bash
sudo s deploy
sudo s invoke -e "test"
sudo s remove

Custom Domain Binding (Avoid Default Domain Forced Download)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Piping confirmation into npx -y @serverless-devs/s deploy executes an unpinned package version non-interactively, reducing opportunities for user review while fetching and running remote code. Because the command performs deployment actions against cloud resources, a malicious upstream package could both run arbitrary code and misuse configured credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions tell users to configure Alibaba Cloud credentials using AccountID/AK/SK but provide no warning about secure handling, least-privilege use, or avoiding exposure in shells, logs, screenshots, or shared environments. In a setup guide for deployment tooling, this omission can lead users to paste long-lived cloud access keys into insecure contexts, increasing the risk of credential leakage and cloud account compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The heading is written only in Chinese ("官方文档来源(用于后续更新)"), which imposes a specific language choice in the skill artifact without offering an alternative or opt-in. The file does not document that this locale restriction is intentional or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.