Back to skill

Security audit

Aliyun Hbr Backup

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alibaba Cloud Backup helper that can use cloud credentials and write local API/output artifacts when directed.

Install this only if you want an agent to help operate Alibaba Cloud HBR. Use temporary or least-privilege Alibaba Cloud credentials, confirm the exact account, region, resource IDs, and whether the action is read-only or mutating before running it, and review output/aliyun-hbr-backup/ before sharing or committing those files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill instructs use of environment credentials, network access, and local file writes, but does not declare permissions or clearly constrain those capabilities. This creates hidden execution power that can surprise the calling system or user, increasing the risk of unintended credential use, outbound requests, or artifact persistence.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill is presented as a Cloud Backup management skill, but the described executable flow centers on enumerating OpenAPI metadata from api.aliyun.com and writing API inventories to disk rather than directly managing user HBR resources. That mismatch can mislead operators and orchestration systems about what the skill will actually do, enabling unnecessary external communication and data generation outside the expected task scope.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation text is broad enough to trigger on many generic backup or troubleshooting requests, which may cause the wrong skill to be selected automatically. Over-broad matching increases the chance that credentials, network access, or write-capable behavior are invoked in contexts where the user did not intend to use this specific Alibaba Cloud HBR workflow.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.