Back to skill

Security audit

Alibaba Cloud Data Analytics Dataanalysisgbi

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alibaba Cloud DataAnalysisGBI helper skill; it has cloud-management risk, but the behavior is coherent with its stated purpose.

Install only if you intend to manage Alibaba Cloud DataAnalysisGBI resources. Use least-privilege Alibaba credentials, review any generated files under output/aliyun-gbi-analytics, and require explicit confirmation before Create, Update, Modify, Set, or other mutating API calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill instructs use of environment variables for Alibaba Cloud credentials, writes artifacts to local output directories, and performs network access to Alibaba metadata endpoints, yet it declares no explicit permissions. This weakens security review and consent boundaries because operators may invoke a skill with credential, filesystem, and network access without clear disclosure of those capabilities.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The skill is presented as managing DataAnalysisGBI resources, but the documented executable path is metadata discovery that contacts api.aliyun.com/meta and writes local API inventory artifacts. This mismatch can mislead users and security tooling about what the skill actually does, increasing the chance of unintended network access, data collection, and misuse under a broader cloud-management pretext.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The activation condition is broad enough to trigger on general Alibaba Cloud management requests, even though the skill is specific to one service and currently emphasizes API metadata discovery. Overbroad routing can cause the wrong skill to handle user requests, exposing credentials, performing unexpected network actions, or producing irrelevant artifacts in unrelated cloud workflows.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The markdown directs users toward create/update/modify/set operations and local artifact writes, but it does not include a clear user-facing warning that these actions may change cloud resources and persist potentially sensitive operational data. In a cloud skill that uses account credentials, missing warnings increase the risk of accidental destructive changes and inadvertent storage of identifiers or API outputs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.