Back to skill

Security audit

Alibaba Cloud Storage OSS Ossutil

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Alibaba Cloud OSS command-line helper, but users should take care with the privileged installer, downloaded binary, credentials, and destructive OSS commands.

Before installing, verify the ossutil download against official Alibaba Cloud guidance, prefer a user-owned install path when possible, and only use least-privilege RAM credentials. Be careful with examples that upload, sync, change ACLs, or use --delete, and avoid saving secrets or overly broad object listings in evidence files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/install.md:13
Finding

Downloaded ossutil Executable Is Installed and Run Without Integrity Verification

Content
View full analysis
Remediation
View remediation
' 'ossutil.zip' | sha256sum --check --strict - unzip ossutil.zip ``` 3. Prefer verification using a vendor-provided cryptographic signature whose public key is obtained through an independently authenticated channel. 4. Do not place the executable in `/usr/local/bin` unless verification succeeds. 5. Extract into a newly created private temporary directory and inspect the expected archive layout before moving any file. 6. Prefer an authenticated, vendor-supported package repository where available, while retaining package signature verification. 7. Document separate pinned checksums for Linux and macOS artifacts and update them through a controlled release process. 8. Where practical, run the version check and initial validation in a restricted environment before granting the binary access to Alibaba Cloud credentials. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/install.md (reported line 11)May include surrounding context.

md
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi
curl -fL -o ossutil.zip https://gosspublic.alicdn.com/ossutil/v2/2.2.1/ossutil-2.2.1-linux-amd64.zip
unzip ossutil.zip

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires shell execution and file writing but does not declare any explicit tool scope or permission boundaries. In a credential-handling CLI skill, this creates unnecessary ambiguity about what the agent may execute or persist, increasing the chance of overbroad command execution, unsafe file writes, or accidental exposure of OSS credentials and object data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The installation instructions perform system-level package installation and place a binary into /usr/local/bin using sudo, but provide no warning that they will modify the host system or require elevated privileges. In a skill context, users may paste commands directly; lack of explicit warning increases the risk of unintended privileged changes on the local machine.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 9)May include surrounding context.

bash
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 15)May include surrounding context.

bash
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 16)May include surrounding context.

bash
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 25)May include surrounding context.

bash
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 26)May include surrounding context.

bash
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 11)May include surrounding context.

md
if command -v yum >/dev/null 2>&1; then
  sudo yum install -y unzip
else
  sudo apt-get update && sudo apt-get install -y unzip
fi
curl -fL -o ossutil.zip https://gosspublic.alicdn.com/ossutil/v2/2.2.1/ossutil-2.2.1-linux-amd64.zip
unzip ossutil.zip

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to download a remote zip and immediately proceed to unzip, chmod, move, and version-check the resulting binary without any authenticity or integrity verification steps. This is dangerous because users are encouraged to trust and install a network-fetched executable into PATH, making supply-chain compromise or mirror tampering more impactful.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 15)May include surrounding context.

fi curl -fL -o ossutil.zip https://gosspublic.alicdn.com/ossutil/v2/2.2.1/ossutil-2.2.1-linux-amd64.zip unzip ossutil.zip sudo chmod 755 ossutil-2.2.1-linux-amd64/ossutil sudo mv ossutil-2.2.1-linux-amd64/ossutil /usr/local/bin/ossutil ossutil version

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install.md (reported line 25)May include surrounding context.

fi curl -fL -o ossutil.zip https://gosspublic.alicdn.com/ossutil/v2/2.2.1/ossutil-2.2.1-linux-amd64.zip unzip ossutil.zip sudo chmod 755 ossutil-2.2.1-linux-amd64/ossutil sudo mv ossutil-2.2.1-linux-amd64/ossutil /usr/local/bin/ossutil ossutil version

text

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/check_ossutil.py (reported line 29)May include surrounding context.

python
binary = shutil.which("ossutil")
        lines.append(f"ossutil_path={binary or 'NOT_FOUND'}")
        if binary:
            proc = subprocess.run([binary, "--version"], capture_output=True, text=True, check=False)
            lines.append(f"ossutil_version_exit={proc.returncode}")
            lines.append(proc.stdout.strip() or proc.stderr.strip())

Static analysis

No suspicious patterns detected.