Back to skill

Security audit

Aliyun Skills

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Alibaba Cloud CLI helper, but it needs review because it gives high-impact cloud administration commands with incomplete safety and secret-handling guidance.

Install only if you intend to let the agent help operate Alibaba Cloud resources. Use least-privilege RAM users or roles, avoid root or AdministratorAccess unless explicitly required, verify regions and resource IDs before any mutating command, list targets before bulk deletion, keep backups or rollback plans for databases, storage, DNS, and registries, and avoid putting real passwords or tokens directly in shell commands or shared transcripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Warning
Location
references/setup.md:16
Finding

Aliyun CLI Binary Installed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: references/setup.md:16-23
Vulnerability Type: Unverified third-party binary installation
Risk Level: Medium

Vulnerable Code

bash
# Option 2: manual binary install (amd64)
curl -Lo aliyun-cli.tgz https://github.com/aliyun/aliyun-cli/releases/latest/download/aliyun-cli-linux-latest-amd64.tgz
tar xzf aliyun-cli.tgz
sudo mv aliyun /usr/local/bin/

# For arm64
curl -Lo aliyun-cli.tgz https://github.com/aliyun/aliyun-cli/releases/latest/download/aliyun-cli-linux-latest-arm64.tgz
tar xzf aliyun-cli.tgz
sudo mv aliyun /usr/local/bin/

Technical Analysis

The installation instructions retrieve a binary archive from a mutable latest release URL, extract it, and move the resulting executable into the privileged /usr/local/bin directory. No cryptographic checksum, digital signature, pinned version, or archive-content validation is performed.

Although the URL points to the official Aliyun CLI GitHub repository, the process does not independently verify artifact integrity. Compromise of the upstream release account, release pipeline, hosted artifact, or another trusted delivery component could therefore result in an altered executable being installed.

Moving the unchecked executable into /usr/local/bin also gives it a trusted position in the system command search path. When subsequently invoked, the binary may have access to Alibaba Cloud credentials, profiles, environment variables, and all cloud privileges assigned to the current identity.

Attack Path

  1. An attacker compromises or replaces an artifact available through the mutable release URL or another trusted supply-chain component.
  2. A user follows the documented installation procedure.
  3. The modified archive is downloaded without checksum or signature validation.
  4. The attacker-controlled executable is installed as /usr/local/bin/aliyun.
  5. The user invokes aliyun while authenticate ...[truncated 938 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the download to an explicit, reviewed Aliyun CLI version instead of using a mutable latest URL.
  • Obtain the expected SHA-256 digest from an authenticated, publisher-controlled source.
  • Verify the digest before extraction and terminate installation on mismatch.
  • Verify a publisher-provided digital signature when available.
  • Extract into a newly created restricted temporary directory and validate the archive contents before installation.
  • Ensure that the archive cannot overwrite paths outside the intended extraction directory.
  • Prefer a trusted package manager that validates signed repository metadata and package integrity.
  • Document the expected version after installation and confirm it with aliyun version.

T09 · Insecure Skill Coding Practices

Warning
Location
references/acr.md:58
Finding

Temporary Registry Token Exposed Through Docker Command Arguments

Content
View full analysis

Vulnerability Details

File Location: references/acr.md:58-64
Vulnerability Type: Sensitive token passed through process arguments
Risk Level: Medium

Vulnerable Code

bash
TOKEN=$(aliyun cr GetAuthorizationToken --region cn-hangzhou --InstanceId cri-xxxx \
  | jq -r '.AuthorizationToken')

docker login \
  --username=cr_temp_user \
  --password="$TOKEN" \
  myinstance-registry.cn-hangzhou.cr.aliyuncs.com

The same unsafe authentication pattern is repeated at references/acr.md:244-247.

Technical Analysis

The temporary ACR authorization token is passed to Docker through the --password command-line option. Shell expansion places the token in the resulting process argument vector. Depending on the operating system, process-observation permissions, CI configuration, terminal recording, and diagnostic tooling, command arguments may be visible to other local processes or recorded in logs.

The token is also stored in a shell variable for the remainder of the shell session unless explicitly removed. While the token is documented as valid for one hour, it remains a usable bearer credential during that validity window.

Attack Path

  1. A user requests a temporary ACR authorization token and stores it in TOKEN.
  2. The shell expands $TOKEN into the docker login --password argument.
  3. A local observer, process-monitoring service, CI logger, shell tracing facility, or diagnostic collector captures the command arguments.
  4. The observer extracts the registry token before it expires.
  5. The attacker authenticates to the specified registry as cr_temp_user.
  6. The attacker performs registry operations allowed by the issued token.

Impact Assessment

An attacker who captures the token may obtain temporary access to the ACR Enterprise Edition registry. The precise impact depends on the token's granted permissions and may include:

  • Pulling private container images.
  • Learni ...[truncated 369 chars]
Remediation
View remediation

Remediation Suggestions

Use Docker's standard-input authentication mechanism so the token is not placed in the command argument vector:

bash
aliyun cr GetAuthorizationToken \
  --region cn-hangzhou \
  --InstanceId cri-xxxx |
  jq -r '.AuthorizationToken' |
  docker login \
    --username cr_temp_user \
    --password-stdin \
    myinstance-registry.cn-hangzhou.cr.aliyuncs.com

Additional hardening should include:

  • Disable shell tracing before handling credentials.
  • Ensure CI systems mask registry tokens and do not log command output.
  • Avoid storing the token in a long-lived shell variable.
  • If a variable is required, clear it immediately with unset TOKEN.
  • Use the shortest practical token lifetime and least-privileged registry permissions.
  • Update both occurrences of the unsafe pattern in references/acr.md.

T09 · Insecure Skill Coding Practices

Warning
Location
references/acr.md:70
Finding

Permanent ACR Password Passed as a Plain Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: references/acr.md:70-73
Vulnerability Type: Persistent credential exposed through command arguments
Risk Level: Medium

Vulnerable Code

bash
aliyun cr ResetLoginPassword \
  --region cn-hangzhou \
  --InstanceId cri-xxxx \
  --Password 'NewP@ss123!'

Technical Analysis

The example supplies a permanent registry login password directly on the command line. This may expose the password through shell history, terminal transcripts, CI job logs, command auditing, or process inspection. Unlike the temporary token in the preceding example, a permanent login password remains useful until rotated.

The literal example also models a fixed, human-composed password. Although it appears to be a placeholder rather than a real secret embedded in the project, copying it without replacement would create a predictable credential.

Attack Path

  1. A user substitutes a real permanent password into the documented command.
  2. The command is retained in shell history or captured by process, terminal, audit, or CI logging.
  3. An attacker with access to those records obtains the ACR password.
  4. The attacker authenticates to the corresponding registry endpoint.
  5. Registry operations are performed until the password is rotated or disabled.

Impact Assessment

Exposure may provide persistent ACR registry access under the affected account. Depending on registry permissions, an attacker may read private images, push modified images, or interfere with image availability. If production systems automatically deploy mutable image tags, unauthorized image pushes could lead to downstream workload compromise.

Remediation
View remediation

Remediation Suggestions

  • Do not place permanent passwords directly in example command lines.
  • Prefer an interactive, non-echoing password prompt if the CLI supports it.
  • Otherwise retrieve the password at runtime from a protected secret manager and use a CLI-supported standard-input or protected file mechanism.
  • If the Aliyun API only accepts the password as an argument, warn users about process and history exposure, temporarily disable shell history and tracing, and run the command only on a trusted host.
  • Generate a unique, high-entropy password instead of using the documented literal value.
  • Rotate the password immediately if it appears in logs or shell history.
  • Prefer temporary authorization tokens over permanent registry passwords where operationally possible.

T09 · Insecure Skill Coding Practices

Warning
Location
references/ram.md:43
Finding

RAM Console Password Passed as a Plain Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: references/ram.md:43-47
Vulnerability Type: User credential exposed through command arguments
Risk Level: Medium

Vulnerable Code

bash
aliyun ram CreateLoginProfile \
  --UserName alice \
  --Password "P@ssw0rd!" \
  --PasswordResetRequired true

Technical Analysis

A RAM user's console password is included directly in the Aliyun CLI command. Real passwords substituted into this pattern may be retained in shell history or captured through command logging, terminal recording, process observation, or CI output.

Requiring a password reset on first login reduces the duration of exposure but does not eliminate the issue. An attacker who obtains the initial password before the legitimate user completes the reset may be able to log in first. The displayed password is illustrative, but it is predictable and should not be presented as a reusable credential pattern.

Attack Path

  1. An administrator runs the command with a real initial RAM password.
  2. The command is captured in shell history, process telemetry, an audit trail, or automation logs.
  3. An attacker obtains the username and initial password before the intended user changes it.
  4. The attacker logs into the Alibaba Cloud console as the RAM user.
  5. The attacker uses the user's attached policies to access or modify cloud resources.

Impact Assessment

Exploitation grants the effective privileges assigned to the RAM user. Depending on attached policies, this could range from access to a limited service to broad control of ECS, OSS, RDS, VPC, or identity resources. If the user has RAM administration privileges, the attacker may be able to create additional credentials or expand access.

Remediation
View remediation

Remediation Suggestions

  • Replace the literal password example with instructions to generate a unique, high-entropy value.
  • Use an interactive, non-echoing prompt or a supported protected-input mechanism rather than a command argument.
  • Deliver initial credentials to the user through a separate, secure channel.
  • Retain --PasswordResetRequired true and enforce multi-factor authentication for console access.
  • Grant the RAM user only the minimum required policies.
  • Ensure automation systems redact password parameters from logs.
  • Rotate the password immediately if command history or logs may have captured it.

T09 · Insecure Skill Coding Practices

Warning
Location
references/rds.md:108
Finding

RDS Account Passwords Passed as Plain Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: references/rds.md:108-136
Vulnerability Type: Database credentials exposed through command arguments
Risk Level: Medium

Vulnerable Code

Account creation uses a command-line password:

bash
aliyun rds CreateAccount \
  --RegionId cn-hangzhou \
  --DBInstanceId rm-xxxxxx \
  --AccountName appuser \
  --AccountPassword "P@ssw0rd!" \
  --AccountType Normal \
  --AccountDescription "Application user"

Password reset uses the same unsafe pattern:

bash
aliyun rds ResetAccountPassword \
  --RegionId cn-hangzhou \
  --DBInstanceId rm-xxxxxx \
  --AccountName appuser \
  --AccountPassword "NewP@ss!"

Technical Analysis

Both account creation and password reset place the RDS password in the process argument vector. Real credentials substituted into these examples may be exposed through shell history, process inspection, command auditing, terminal capture, or CI logs.

The literal values are illustrative rather than confirmed production secrets, but they model weak and predictable password choices. Password reset operations are particularly sensitive because a newly rotated credential can immediately be disclosed by the same command used to set it.

Attack Path

  1. An operator creates or resets an RDS account using a real password in the documented argument.
  2. The command is stored in shell history or captured by local monitoring, terminal recording, or automation logs.
  3. An attacker with access to those records obtains the database account name and password.
  4. The attacker identifies or reaches an RDS connection endpoint allowed by the instance network and IP whitelist.
  5. The attacker authenticates and performs operations permitted by the database account.

Impact Assessment

Exploitation requires network reachability to the RDS endpoint in addition to the captured credentials. If reachable, impact is governed by the a ...[truncated 285 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not include reusable password literals in documentation.
  • Generate unique, high-entropy database passwords through a cryptographically secure password generator.
  • Prefer an interactive, non-echoing prompt or a CLI-supported standard-input or protected-file mechanism.
  • Retrieve credentials at runtime from a secret manager when commands are automated.
  • Disable shell tracing and prevent CI systems from echoing expanded command arguments.
  • Restrict RDS network access to necessary VPC ranges and narrowly scoped IP whitelist entries.
  • Grant each database account only the minimum required database privileges.
  • Rotate any password that may have entered shell history, process telemetry, or logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (42)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/ecs.md (reported line 124)May include surrounding context.

For Linux with xfs

sudo xfs_growfs /mount/point

For system disk with growpart

sudo growpart /dev/vda 1 && sudo resize2fs /dev/vda1

text

### Offline resize (requires stopping the instance first)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/oss.md (reported line 53)May include surrounding context.

bash
# Delete all objects first
ossutil rm oss://my-bucket --all-type --recursive --force

# Then delete the bucket
ossutil rb oss://my-bucket

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/oss.md (reported line 139)May include surrounding context.

bash
# Delete single object
ossutil rm oss://my-bucket/file.txt

# Delete all objects matching a prefix
ossutil rm oss://my-bucket/logs/ --recursive --force

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The recursive forced deletion example can remove all objects under a prefix without interactive confirmation, which materially increases the risk of mass data loss from copy-paste or path mistakes. In a cloud admin skill, such commands are especially dangerous because they are likely to be executed directly against production storage.

Content

Scanner excerpt · references/oss.md (reported line 142)May include surrounding context.

ossutil rm oss://my-bucket/file.txt

Delete all objects matching a prefix

ossutil rm oss://my-bucket/logs/ --recursive --force

text

### Object Metadata / Properties

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill auto-activates on essentially any mention of Alibaba Cloud services or related product names, which is broader than necessary for a command-executing infrastructure skill. Overbroad activation can route unrelated conversations into a high-impact cloud-management context, increasing the chance of unintended command generation, credential handling, or destructive guidance when the user did not explicitly ask to use the CLI.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes namespace deletion commands without any warning that the action is destructive and may remove or disrupt access to associated repositories and workflows. In an operational CLI skill, users may copy-paste commands directly, increasing the likelihood of accidental destructive actions against production registries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The repository deletion command is destructive and presented without cautionary context. In a cloud-management skill, this can lead to accidental deletion of container repositories, breaking image distribution, deployments, and recovery processes if users execute the example against live environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide shows how to enable a public Internet endpoint for the registry without warning that this increases attack surface and may expose the service to unauthorized access attempts if ACLs, credentials, or network restrictions are weak. In a cloud CLI skill, operational users may enable exposure quickly without understanding security implications, making this more dangerous than a generic reference document.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This reference file includes direct commands to add, update, disable, and delete DNS records, but it does not warn that these operations can immediately disrupt production traffic, email delivery, certificate validation, or service availability. In a CLI skill intended to help users manage live Alibaba Cloud resources, omission of safety guidance increases the chance that an agent or user will execute destructive DNS changes without understanding rollback needs or blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file documents StopInstance --ForceStop true as equivalent to powering off an instance, but it does not explicitly warn that forcing shutdown can interrupt writes and risk data corruption. Because this behavior can affect user data and system integrity, the skill description should disclose that risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The RebootInstance example with --ForceReboot true performs a disruptive operation that can terminate active processes and interrupt writes. The markdown explains when to use it but does not warn users about the operational and data integrity risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes a DeleteSnapshot command, which is a destructive operation affecting recoverability of user data. The surrounding description provides no caution, confirmation note, or impact warning, so users are not alerted to the risk before running it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file includes destructive deletion commands for OSS objects and recursive prefix removal without consistently highlighting the risk of irreversible data loss. In an operational cloud skill, users may copy these commands directly, making accidental deletion of large datasets more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example sets an object ACL to public-read without warning that this makes the object readable by anyone on the internet. In an OSS management reference, that omission can directly cause unintended public exposure of private files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to generate presigned download URLs that can be used without authentication, but it does not warn that anyone possessing the URL can access the object until expiry. In a cloud administration skill, this omission can easily lead to unintended external data exposure, especially if users share links in tickets, chat, or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes examples for creating console passwords and access keys, including a hardcoded sample password, without emphasizing that these are sensitive credentials that must not be embedded in docs, shell history, logs, or shared transcripts. In a CLI skill that may be copied verbatim by users or agents, this increases the risk of insecure credential handling and accidental exposure of long-lived secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples attach powerful system policies such as AdministratorAccess without any warning about least privilege, blast radius, or the risks of granting broad rights to users. In an Alibaba Cloud management skill, users may copy these commands directly, making privilege escalation or overprovisioning more likely and increasing the impact of account compromise or operator error.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/rds.md (reported line 45)May include surrounding context.

--DBInstanceNetType Intranet
--VPCId vpc-xxxxxx
--VSwitchId vsw-xxxxxx
--SecurityIPList "10.0.0.0/8"
--DBInstanceDescription "My MySQL instance"
--PayType Postpaid

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/slb.md (reported line 73)May include surrounding context.

--DBInstanceNetType Intranet
--VPCId vpc-xxxxxx
--VSwitchId vsw-xxxxxx
--SecurityIPList "10.0.0.0/8"
--DBInstanceDescription "My MySQL instance"
--PayType Postpaid

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/slb.md (reported line 86)May include surrounding context.

--DBInstanceNetType Intranet
--VPCId vpc-xxxxxx
--VSwitchId vsw-xxxxxx
--SecurityIPList "10.0.0.0/8"
--DBInstanceDescription "My MySQL instance"
--PayType Postpaid

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The database deletion example shows a destructive command without an explicit warning that deleting the database will permanently remove its contents. In a CLI reference skill used to manage production cloud databases, omission of a deletion/data-loss warning can lead to accidental destructive actions by users copying commands verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The account creation example includes a plaintext password directly on the command line without warning that command-line arguments may be exposed via shell history, process listings, logs, or transcripts. In an agent skill context, users may reuse the example with real credentials, increasing the chance of credential leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The password reset example similarly embeds a plaintext password in the CLI command and lacks any warning about sensitive credential exposure. This can disclose newly rotated credentials through terminal history, process inspection, CI logs, or agent conversation artifacts, undermining the security benefit of rotation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.