T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Third-Party CLI Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not clearly malicious, but it needs review because it asks for cloud credentials and gives broad shell/CLI instructions that could expose secrets or change cloud/local state.
Install only after reviewing the CLI package source/version, use least-privileged short-lived Aliyun credentials, avoid putting secrets in command-line arguments, require confirmation before any local mapping update, and restrict the skill to read-only log commands unless you explicitly need administrative SLS operations.
SKILL.md:8Unpinned Third-Party CLI Dependency
SKILL.md:48Aliyun Access Credentials Passed Through Command-Line Arguments
SKILL.md:75Shell Command Injection Through Unvalidated Query Template Interpolation
This markdown file uses Chinese for the skill description, setup, and operating instructions, and does not indicate that users may choose another language. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue.
The skill is described as being for querying and analyzing Alibaba Cloud logs, but it also documents a generic SDK-to-CLI mapping that includes write-capable operations such as create_logstore. In an agent context, this expands the tool from read-only inspection into state-changing administration, increasing the risk of unauthorized or accidental modification if the agent generalizes from the documentation and executes destructive commands.
The instruction is explicitly scoped to cases where users mention Chinese project names, reflecting a language-specific behavior. The file does not offer users a language/locale choice or explain why this locale restriction is required, which can violate language policy requirements.
The documentation expands the skill from read-only log querying into persistent repository modification by instructing it to append new mappings to a local file. That creates an unnecessary write capability and a path for prompt-driven state changes, which can be abused to poison future behavior, introduce incorrect routing metadata, or create unauthorized repo changes.
The documentation says the skill will convert user input into a WHERE clause with an appended LIMIT, but later examples allow passing full SQL directly. This inconsistency can let untrusted input bypass intended query-shaping safeguards, including LIMIT enforcement, and enables broader or more expensive queries than the surrounding safety guidance suggests.
The file tells the agent to modify repository content without clearly disclosing that this action changes local state and persists beyond the current query. Even if the intended change is simple, hidden persistence increases the risk of unintended edits, audit gaps, and user-driven repository tampering through normal skill usage.
No suspicious patterns detected.