Back to skill

Security audit

Aliyun TTS

Security checks for vulnerabilities and agentic risk

Overview

This Alibaba Cloud text-to-speech skill is purpose-aligned, but it sends its token request over unencrypted HTTP, which can expose temporary service credentials on the network.

Review this skill before installing. It appears intended to perform Alibaba Cloud TTS, but users should not use it on untrusted networks unless the token request is changed to HTTPS. Treat Aliyun secrets as account-sensitive, store them only in trusted configuration, avoid sharing or committing config files, and rotate credentials if they may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
aliyun_tts.py:76
Finding

Alibaba Cloud Token Request Uses Unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: aliyun_tts.py, lines 76–80
Vulnerability Type: Plaintext transmission of authentication material
Risk Level: High

python
full_url = f"http://nls-meta.{REGION}.aliyuncs.com/?Signature={signature}&{query_string}"

host = f"nls-meta.{REGION}.aliyuncs.com"
conn = http.client.HTTPConnection(host)
conn.request("GET", full_url)
resp = conn.getresponse()

Technical Analysis

The skill retrieves an Alibaba Cloud bearer token through an unencrypted HTTP connection. The request exposes the access-key ID, HMAC signature, nonce, timestamp, and other authentication metadata to any party capable of observing network traffic. More importantly, the token returned by the service is also transmitted without transport encryption.

Although the access-key secret itself is not directly included in the request, an on-path attacker can capture the returned bearer token. The Base64 operation at line 73 is a normal encoding step for the HMAC-SHA1 request signature and is not, by itself, a covert exfiltration mechanism. The security issue is that the resulting authentication exchange occurs over plaintext HTTP.

The use of HTTPConnection also provides no TLS certificate authentication or transport integrity. An active attacker could inspect or alter the token-service response, steal a valid token, or return a forged response that causes synthesis requests to fail.

Attack Path

  1. The victim invokes the skill to synthesize speech.
  2. The skill sends a signed CreateToken request to nls-meta.cn-shanghai.aliyuncs.com over plaintext HTTP.
  3. An attacker on the same network, a compromised proxy, or another on-path system observes or intercepts the connection.
  4. The attacker captures the token returned in the plaintext response.
  5. While the token remains valid, the attacker combines it with the relevant application key and submits unauthorized requests to the Alibaba Cloud T ...[truncated 633 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace http.client.HTTPConnection(host) with http.client.HTTPSConnection(host, timeout=...).
  • Send only the origin-form request path rather than a plaintext http:// absolute URL.
  • Rely on Python's validated default TLS context, or explicitly create a secure context with hostname and certificate verification enabled.
  • Never permit fallback or redirects from HTTPS to HTTP.
  • Add connection and read timeouts and close the connection reliably.
  • Avoid logging signed request URLs, token responses, or bearer tokens.
  • Rotate credentials and invalidate active tokens if this implementation has been used on an untrusted network.

Example hardened structure:

python
request_path = f"/?Signature={signature}&{query_string}"
conn = http.client.HTTPSConnection(host, timeout=10)
try:
    conn.request("GET", request_path)
    resp = conn.getresponse()
    body = resp.read().decode("utf-8")
finally:
    conn.close()

T09 · Insecure Skill Coding Practices

Note
Location
aliyun_tts.py:54
Finding

UUIDv1 Nonce May Disclose a Stable Host Identifier

Content
View full analysis

Vulnerability Details

File Location: aliyun_tts.py, line 54
Vulnerability Type: Host metadata disclosure through UUIDv1
Risk Level: Low

python
params = {
    'AccessKeyId': ALIYUN_ACCESS_KEY_ID,
    'Action': 'CreateToken',
    'Format': 'JSON',
    'RegionId': REGION,
    'SignatureMethod': 'HMAC-SHA1',
    'SignatureNonce': str(uuid.uuid1()),
    'SignatureVersion': '1.0',
    'Timestamp': time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime()),
    'Version': '2019-02-28'
}

Technical Analysis

uuid.uuid1() generates a time-based UUID. Depending on the Python runtime and host configuration, its node component may be derived from a network interface's MAC address or another stable node identifier.

The nonce only needs to be unique and unpredictable enough for the authentication protocol. Embedding a potentially stable host-derived identifier is unnecessary for the skill's declared TTS functionality and can permit correlation of requests originating from the same system.

Attack Path

  1. The victim invokes the skill and it creates a signed token request containing a UUIDv1 nonce.
  2. Alibaba Cloud, a logging intermediary, or a network observer obtains the nonce.
  3. The observer extracts the UUID version, timestamp fields, and node component.
  4. If the node component is stable, the observer correlates separate requests as originating from the same host.
  5. If the runtime used a hardware-derived node value, the observer may also infer MAC-related metadata.

Impact Assessment

This issue does not provide code execution, local privileges, or access to the Alibaba Cloud account. Its impact is limited to avoidable host fingerprinting and cross-request correlation. The exact disclosure is environment-dependent because UUIDv1 generation does not always use a hardware MAC address.

Remediation
View remediation

Remediation Suggestions

Replace the time- and node-based UUID with a random nonce that does not encode host metadata:

python
'SignatureNonce': str(uuid.uuid4()),

If stronger control over nonce size or representation is required, use the secrets module:

python
import secrets

'SignatureNonce': secrets.token_hex(16),

Ensure the selected nonce format remains compatible with Alibaba Cloud's request-signing specification.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares capabilities that rely on environment secrets and outbound network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill's operational and security boundaries less transparent, increasing the chance that an agent can invoke it with broader access than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation tells users to store an access key secret in skill configuration and a local JSON file without any warning about credential sensitivity, file permissions, redaction, rotation, or avoiding accidental disclosure. This can lead to secrets being exposed through screenshots, logs, backups, shell history, or overly permissive local files, enabling unauthorized use of the Alibaba Cloud account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The token acquisition request is sent over plain HTTP using http.client.HTTPConnection to nls-meta.cn-shanghai.aliyuncs.com, so the signed request metadata and returned access token can be intercepted or modified by an on-path attacker. Even if the TTS text itself is sent later over HTTPS, compromise of the token request can enable unauthorized API use, token theft, or tampering with authentication flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.