Back to skill

Security audit

alibaba devops

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Alibaba Cloud DevOps connector, but it gives an agent broad token-backed control over code, pipelines, deployments, and ownership without enough safety guidance.

Install only if you trust the external npm MCP package and are comfortable giving an agent access to Alibaba Cloud Yunxiao. Use a minimally scoped token, avoid pasting real tokens into prompts or logged commands, and require explicit human approval before delete, deploy, pipeline-run, resource-member, validation, or ownership-change actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents a very large number of state-changing and destructive operations such as deleting branches/files, modifying pipelines, changing resource ownership, and executing deployments, but it does not warn users about irreversible effects or recommend confirmation before execution. In an MCP/agent context, this increases the chance of accidental high-impact actions because users may treat the tool list as routine capabilities rather than operations requiring explicit approval.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation instructs users to pass `YUNXIAO_ACCESS_TOKEN` via environment variables and CLI examples without any warning about credential sensitivity, storage, shell history exposure, or scope minimization. In agent-driven workflows, this can lead to unsafe token handling, accidental leakage in logs, copied commands, or overprivileged credentials being used broadly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.