Back to skill

Security audit

ctyun-cli-天翼云-命令行

Security checks across malware telemetry and agentic risk

Overview

This is a coherent cloud CLI skill, but users should handle cloud credentials and debug logs carefully.

Install only if you intend to manage Tianyi Cloud resources from this environment. Use least-privilege cloud keys, avoid passing secrets directly as command arguments, protect any saved profiles or shell startup files, and do not share debug logs without reviewing them for credentials or account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents passing access keys and secret keys on the command line during interactive configuration. Command-line secrets can be exposed via shell history, process listings, terminal logging, and audit tooling, which is a real credential-handling risk for a cloud administration CLI. Because this tool manages high-value cloud resources, leaked credentials could enable broad account compromise.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation advertises a debug flag without warning that debug output may include request headers, payloads, endpoints, or authentication material. In a cloud CLI context, users often paste debug logs into tickets or shared chats, so sensitive data may be unintentionally disclosed and reused by an attacker.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.