Back to skill

Security audit

Alibaba Cloud AI PAI Aiworkspace

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alibaba Cloud PAI AIWorkspace management skill with expected credential use and local output, but users should carefully confirm any cloud-changing actions.

Install only if you want an agent to help manage Alibaba Cloud PAI AIWorkspace. Use least-privilege credentials, verify the account, region, resource IDs, API name, and parameters before any create/update/modify/set operation, and review files written under output/aliyun-pai-workspace/ before sharing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares no permissions while explicitly instructing use of environment variables for cloud credentials, network-based OpenAPI access, and local file writes under an output directory. This mismatch weakens reviewability and consent because operators may not realize the skill can access secrets, contact external services, and persist data locally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding
The skill is presented as an AIWorkspace management tool, but its documented executable path emphasizes metadata discovery, API enumeration, and local artifact generation. This behavior gap can mislead users into authorizing broader reconnaissance and external data retrieval than expected, increasing the chance of unintended disclosure or misuse.

Vague Triggers

Medium
Confidence
75% confidence
Finding
The invocation criteria are broad enough to trigger the skill for many AIWorkspace-related requests, including troubleshooting and automation, without clearly limiting when credentialed API access or mutating actions should occur. Overbroad routing increases the chance the skill is selected in inappropriate contexts and performs cloud-connected actions with more access than needed.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.