Back to skill

Security audit

Alibaba Cloud AI PAI Aiworkspace

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Alibaba Cloud PAI AIWorkspace helper that uses expected cloud credentials and metadata lookups without hidden persistence or exfiltration behavior.

Install only if you intend to let your agent help manage Alibaba Cloud PAI AIWorkspace. Use least-privilege Alibaba Cloud credentials, review any proposed create/update/modify/set operation before execution, and keep generated outputs under the documented output directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tainted flow: 'timeout' from os.getenv (line 34, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 23)May include surrounding context.

python
def fetch_json(url: str, timeout: int) -> dict:
    req = urllib.request.Request(url, headers={"User-Agent": "codex-skill"})
    with urllib.request.urlopen(req, timeout=timeout) as resp:
        return json.loads(resp.read().decode("utf-8"))

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description suggests an operational AIWorkspace management skill that would inventory, create, update, query status, troubleshoot, or automate lifecycle actions against AIWorkspace resources. The supplied code does not do any of that. Instead, it retrieves API documentation metadata for a product/version (defaulting to AIWorkSpace 2021-02-04) from the Alibaba Cloud OpenAPI metadata service and saves the results locally as JSON and Markdown. While this is related to AIWorkspace in the sense that the default product code targets AIWorkSpace, the primary purpose is API metadata discovery/export, not managing workspace resources. This is a materially different behavior and should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires capabilities that can access environment variables, write files, and make network requests, but it does not declare any tool scope or permissions boundaries. In a credentialed cloud-management context, this creates an authorization blind spot where a caller may not realize the skill can read secrets and perform external requests, increasing the chance of unintended credential use or data exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation text is broad enough to match many generic cloud-management tasks, which can cause the skill to be selected in situations beyond its narrowly intended scope. In a cloud environment with credentials available via environment variables or shared config, over-triggering increases the chance of unnecessary API calls, misuse of privileges, or accidental execution of mutating workflows.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 3)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 4)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 5)May include surrounding context.

md
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/list_openapi_meta_apis.py (reported line 39)May include surrounding context.

python
output_dir.mkdir(parents=True, exist_ok=True)

    url = (
        f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
        f"/versions/{args.version}/api-docs.json"
    )
    payload = fetch_json(url, timeout)

Static analysis

No suspicious patterns detected.