Back to skill

Security audit

阿里云日志查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it asks for cloud credentials and gives broad shell/CLI instructions that could expose secrets or change cloud/local state.

Install only after reviewing the CLI package source/version, use least-privileged short-lived Aliyun credentials, avoid putting secrets in command-line arguments, require confirmation before any local mapping update, and restrict the skill to read-only log commands unless you explicitly need administrative SLS operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party CLI Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:48
Finding

Aliyun Access Credentials Passed Through Command-Line Arguments

Content
View full analysis
\ --access-key= \ --region-endpoint= \ --project= \ --logstore= \ ... ``` The Skill also presents a configuration command that accepts the same credentials as positional command-line arguments: ```bash aliyunlog configure ``` ### Technical Analysis The Skill instructs users to place an Aliyun access ID and access key directly in command-line arguments. Sensitive arguments may be retained in shell history, terminal transcripts, Agent execution logs, audit telemetry, debugging output, or process-monitoring systems. On systems with permissive process visibility, another local principal may also be able to inspect the running command line. The risk is especially significant because Aliyun access keys may be long-lived credentials. If the associated identity has broad SLS or account permissions, disclosure can provide access beyond the specific log query requested by the user. ### Attack Path 1. A user supplies an Aliyun access ID and access key to perform a log query. 2. The Agent inserts those credentials into the documented CLI command. 3. The command is executed with the secrets present in its argument vector. 4. The command is captured in shell history, process telemetry, an execution transcript, or another local monitoring source. 5. An attacker or unauthorized operator reads the recorded arguments. 6. The attacker authenticates to Aliyun using the exposed credentials. 7. The attacker accesses any SLS or other cloud resources permitted by the compromised identity. ### Impact Assessment The attacker obtains the permissions assigned to the exposed Aliyun identity. Potential impact includes unauthorized reading of s ...[truncated 408 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:75
Finding

Shell Command Injection Through Unvalidated Query Template Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese for the skill description, setup, and operating instructions, and does not indicate that users may choose another language. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is described as being for querying and analyzing Alibaba Cloud logs, but it also documents a generic SDK-to-CLI mapping that includes write-capable operations such as create_logstore. In an agent context, this expands the tool from read-only inspection into state-changing administration, increasing the risk of unauthorized or accidental modification if the agent generalizes from the documentation and executes destructive commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instruction is explicitly scoped to cases where users mention Chinese project names, reflecting a language-specific behavior. The file does not offer users a language/locale choice or explain why this locale restriction is required, which can violate language policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation expands the skill from read-only log querying into persistent repository modification by instructing it to append new mappings to a local file. That creates an unnecessary write capability and a path for prompt-driven state changes, which can be abused to poison future behavior, introduce incorrect routing metadata, or create unauthorized repo changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The documentation says the skill will convert user input into a WHERE clause with an appended LIMIT, but later examples allow passing full SQL directly. This inconsistency can let untrusted input bypass intended query-shaping safeguards, including LIMIT enforcement, and enables broader or more expensive queries than the surrounding safety guidance suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file tells the agent to modify repository content without clearly disclosing that this action changes local state and persists beyond the current query. Even if the intended change is simple, hidden persistence increases the risk of unintended edits, audit gaps, and user-driven repository tampering through normal skill usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.