Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 本目录固定使用 `bailian-cli@1.26.0`,传递依赖由 `package-lock.json` 锁定。不要全局安装,不要运行远程安装脚本,也不要调用内置自更新命令。
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a clearly scoped Alibaba Cloud Bailian CLI helper with disclosed cloud data sharing and user-consent checks.
Before installing, understand that using the skill can send prompts, URLs, search queries, generated content, and explicitly approved local files to Alibaba Cloud Bailian, and OAuth login may save a session locally. Only use it with files and accounts you are comfortable sending to that service.
Referenced artifact was not completely inspected
本目录固定使用 `bailian-cli@1.26.0`,传递依赖由 `package-lock.json` 锁定。不要全局安装,不要运行远程安装脚本,也不要调用内置自更新命令。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const skill = fs.readFileSync(path.join(root, 'SKILL.md'), 'utf8');
const pkg = JSON.parse(fs.readFileSync(path.join(root, 'package.json'), 'utf8'));
const lock = JSON.parse(fs.readFileSync(path.join(root, 'package-lock.json'), 'utf8'));
const npmrc = fs.readFileSync(path.join(root, '.npmrc'), 'utf8');
assert.equal(pkg.dependencies['bailian-cli'], '1.26.0');
assert.equal(lock.packages[''].dependencies['bailian-cli'], '1.26.0');
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const skill = fs.readFileSync(path.join(root, 'SKILL.md'), 'utf8');
const pkg = JSON.parse(fs.readFileSync(path.join(root, 'package.json'), 'utf8'));
const lock = JSON.parse(fs.readFileSync(path.join(root, 'package-lock.json'), 'utf8'));
const npmrc = fs.readFileSync(path.join(root, '.npmrc'), 'utf8');
assert.equal(pkg.dependencies['bailian-cli'], '1.26.0');
assert.equal(lock.packages[''].dependencies['bailian-cli'], '1.26.0');
No suspicious patterns detected.