Security audit
qwencloud-usage
Security checks for vulnerabilities and agentic risk
Overview
This skill is a transparent guide for using the QwenCloud CLI to authenticate and view account usage or billing information.
Install only if you trust the QwenCloud CLI and are comfortable letting the agent access QwenCloud account status, quotas, and billing details. Review the global npm install step and credential-storage behavior before use.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
