Back to skill

Security audit

Alibaba Cloud Security Content Moderation Green

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Alibaba Cloud moderation helper that uses credentials and OpenAPI access for its stated cloud-management purpose, with no evidence of hidden exfiltration or persistence.

Install only if you intend to let the agent help with Alibaba Cloud Content Moderation. Use least-privilege Alibaba Cloud credentials, review any create/update/modify actions before execution, and keep generated outputs under the documented output directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tainted flow: 'timeout' from os.getenv (line 34, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 23)May include surrounding context.

python
def fetch_json(url: str, timeout: int) -> dict:
    req = urllib.request.Request(url, headers={"User-Agent": "codex-skill"})
    with urllib.request.urlopen(req, timeout=timeout) as resp:
        return json.loads(resp.read().decode("utf-8"))

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims it manages Alibaba Cloud Green moderation resources and policies, including create/update/status operations, but the described executable behavior is limited to metadata discovery and local artifact generation. This mismatch can mislead operators or orchestrators into granting broader trust or using the skill for production changes when it does not actually implement the advertised controls, increasing the chance of unsafe automation or incorrect security assumptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs use of environment variables, networked OpenAPI access, and writing artifacts to disk, but it declares no explicit tool scope or permissions boundary. That creates an authorization and review gap: an agent may invoke network, read credentials from the environment, and write local files without the skill formally disclosing those capabilities to policy enforcement or the user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 3)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 4)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 5)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 39)May include surrounding context.

python
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code fetches data from a remote API and later persists the full response to disk, which are safety-relevant actions under the code-file warning criteria. While the top-level docstring describes the purpose, there is no explicit runtime disclosure or caution that the script will contact an external service and save output files, so users invoking it may not receive a clear warning at execution time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.