Back to skill

Security audit

Alibaba Cloud Observability SLS Log Query

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Alibaba Cloud SLS log-query helper with expected credential use, but users should restrict credentials, endpoints, and dependency versions.

Install only if you are comfortable letting the skill query SLS with your Alibaba Cloud credentials. Use a dedicated read-only RAM identity, prefer short-lived credentials, set SLS_ENDPOINT only to a trusted Alibaba Cloud SLS endpoint, pin the SDK version before use, and avoid saving or sharing raw log output when logs contain sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Alibaba Cloud SDK Dependency

Content
View full analysis
Remediation
View remediation
" ``` 2. Generate a locked requirements file containing cryptographic hashes and install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Commit the lock file to the Skill package and update it only through a documented dependency-review process. 4. Verify that the package is obtained from the expected official Python package index or a controlled internal mirror. 5. Use automated dependency scanning and review release changes before updating the pinned version. 6. Run the scripts with a dedicated, least-privileged account and narrowly scoped Alibaba Cloud credentials to reduce the impact of dependency compromise. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/query_logs.py:87
Finding

Unrestricted Endpoint Used for Authenticated SLS Requests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of environment variables containing long-lived Alibaba Cloud credentials, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, undeclared access to environment data can enable unintended secret exposure or misuse, especially if downstream scripts print errors, debug state, or are combined with other capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written in Chinese and does not offer any language choice or indicate that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without opt-in or justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.