Back to skill

Security audit

云效 DevOps MCP

Security checks for vulnerabilities and agentic risk

Overview

This Yunxiao MCP skill is purpose-aligned, but it should be reviewed carefully because it can expose a credential-backed DevOps MCP service with broad write powers over unauthenticated HTTP and a mutable container image.

Install only after tightening deployment: bind the MCP server to 127.0.0.1 or place it behind authenticated TLS, use a dedicated least-privileged RAM identity, protect or avoid plaintext .env secrets, pin the server image to a reviewed digest, and require explicit approval before any tool that creates, updates, deploys, or changes repository content. Rotate credentials and check audit logs if this service was exposed on an untrusted network.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
DEPLOY.md:29
Finding

Privileged MCP Service Exposed on All Network Interfaces Without a Documented Authentication or TLS Boundary

Content
View full analysis

Vulnerability Details

File Location: DEPLOY.md:29-36
Vulnerability Type: Unauthenticated exposure of a credential-backed DevOps service over plaintext HTTP
Risk Level: High

Vulnerable Code

yaml
    ports:
      - "3000:3000"
    env_file:
      - .env
    restart: unless-stopped
    command: node dist/index.js --sse
    healthcheck:
      test: ["CMD", "wget", "-q", "--spider", "--timeout=5", "http://localhost:3000/sse"]

The deployment documentation also configures the container with Alibaba Cloud credentials:

yaml
ALIBABA_CLOUD_ACCESS_KEY_ID=<your_access_key_id>
ALIBABA_CLOUD_ACCESS_KEY_SECRET=<your_access_key_secret>
ALIBABA_CLOUD_REGION=cn-hangzhou

Technical Analysis

Docker Compose port syntax of "3000:3000" publishes the container port on all host interfaces by default. Consequently, the MCP SSE endpoint may be reachable from other systems whenever host firewall and network routing rules permit it.

The documented architecture uses plaintext HTTP, and the reviewed client does not supply an authentication token or other client credential when opening the SSE connection or submitting JSON-RPC messages. The deployment configuration also does not place the service behind an authenticated reverse proxy or a TLS termination layer.

This service is particularly sensitive because the container receives Alibaba Cloud RAM AccessKey credentials and exposes tools that can access or modify Yunxiao projects, work items, pipelines, repositories, files, and deployment resources. The effective permissions available through the exposed endpoint are determined by the RAM identity configured in .env.

Attack Path

  1. An operator follows DEPLOY.md and publishes host port 3000 using "3000:3000".
  2. The host is connected to a shared LAN, cloud network, VPN, or public interface where another party can reach TCP port 3000.
  3. An attacker connects to the plaint ...[truncated 1476 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bind the published service exclusively to loopback when it is intended for local use:

    yaml
    ports:
      - "127.0.0.1:3000:3000"
    
  2. If remote access is required, avoid publishing the MCP service directly. Place it behind a hardened reverse proxy or gateway that provides:

    • TLS with certificate validation.
    • Strong client authentication, preferably mutual TLS or short-lived identity tokens.
    • Authorization policies controlling which identities may invoke individual tools.
    • Request size limits, rate limits, and audit logging.
    • Network allowlists or private-network access controls.
  3. Update the client to require HTTPS for non-loopback addresses and to reject insecure remote HTTP endpoints by default.

  4. Use a dedicated, least-privileged RAM identity. Grant only the Yunxiao actions and resources required for the intended workflow, and separate read-only from mutating deployments where practical.

  5. Restrict inbound port 3000 through host and cloud firewalls. Verify from another network host that the endpoint is not unintentionally reachable.

  6. Rotate the AccessKey if the service was previously exposed to an untrusted network, and review Yunxiao and cloud audit logs for unauthorized operations.

T08 · Insecure Dependencies

Warning
Location
DEPLOY.md:26
Finding

Mutable Latest Container Image Executes Unreviewed Code with Cloud Credentials

Content
View full analysis

Vulnerability Details

File Location: DEPLOY.md:26
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

yaml
image: build-steps-public-registry.cn-beijing.cr.aliyuncs.com/build-steps/alibabacloud-devops-mcp-server:latest

Technical Analysis

The deployment uses the mutable latest image tag rather than an immutable image digest. A tag can be reassigned by the registry publisher and therefore does not guarantee that future installations or pulls execute the same container contents that were originally reviewed.

This supply-chain exposure is security-sensitive because the image receives ALIBABA_CLOUD_ACCESS_KEY_ID and ALIBABA_CLOUD_ACCESS_KEY_SECRET from the deployment's .env file. It also implements the remote MCP server, including all tool definitions and tool-call behavior. A compromised, mistakenly replaced, or maliciously updated image could read those environment variables, perform cloud operations, alter MCP responses, or transmit credentials externally.

The audit found no evidence that the named image is currently malicious. The vulnerability is the lack of immutable version and provenance controls.

Attack Path

  1. The registry account, image build pipeline, or upstream publishing process is compromised, or the latest tag is otherwise replaced with an unsafe build.
  2. An operator performs a new deployment, explicitly pulls the image, or recreates the service after obtaining the changed tag.
  3. Docker resolves :latest to the newly published image.
  4. The container starts with access to the .env file containing the Alibaba Cloud RAM AccessKey.
  5. Malicious container code reads the credentials or executes unauthorized actions using them.
  6. The container may additionally present deceptive MCP tools or responses to connected clients.

Impact Assessment

Successful exploitation would provide code execution inside the MCP ...[truncated 799 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the server image to a reviewed immutable digest:

    yaml
    image: build-steps-public-registry.cn-beijing.cr.aliyuncs.com/build-steps/alibabacloud-devops-mcp-server@sha256:<reviewed_digest>
    
  2. Record the corresponding semantic version, digest, release source, and review date in the deployment documentation.

  3. Verify image provenance before deployment using registry signatures or an image-signing framework such as Cosign. Enforce signature verification in the deployment pipeline where possible.

  4. Generate and inspect a software bill of materials, and scan the pinned image for known vulnerabilities before approving upgrades.

  5. Treat updates as explicit security changes: review release notes and image differences, test in an isolated environment, approve the new digest, and then update the pinned value.

  6. Continue using a dedicated least-privileged RAM identity so compromise of the container does not grant broader cloud access than necessary.

  7. Rotate RAM credentials and investigate cloud audit logs if an unexpected image digest has ever run with production credentials.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · DEPLOY.md (reported line 31)May include surrounding context.

md
ports:
      - "3000:3000"
    env_file:
      - .env
    restart: unless-stopped
    command: node dist/index.js --sse
    healthcheck:

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The documentation instructs users to create a local .env file containing long-lived Alibaba Cloud AccessKey credentials in plaintext. This is dangerous because such credentials are high-value secrets that can be exposed through shell history, backups, misconfigured file permissions, accidental commits, or agent/workspace access, enabling unauthorized access to Yunxiao and related cloud resources.

Content

Scanner excerpt · DEPLOY.md (reported line 42)May include surrounding context.

md
start_period: 10s
EOF

cat > .env << 'EOF'
ALIBABA_CLOUD_ACCESS_KEY_ID=<your_access_key_id>
ALIBABA_CLOUD_ACCESS_KEY_SECRET=<your_access_key_secret>
ALIBABA_CLOUD_REGION=cn-hangzhou

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation explicitly states that deployment must be performed manually and that an AI agent must not automatically execute the listed commands. The same file then contains complete command sequences for creating configuration files with credentials and starting the Dockerized server, creating a direct contradiction between the stated operational constraint and the documented executable procedure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes an MCP server with broad operational capabilities but does not declare any explicit tool scope such as permissions or allowed-tools. In agent environments, missing scope boundaries can let the skill be invoked more broadly than intended, increasing the chance of unauthorized or overly powerful actions against projects, pipelines, and repositories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises creation, update, deployment, and repository operations but does not warn users or agents that these actions can modify production-like state. Without side-effect warnings, an agent may treat the capability as informational and execute write operations that alter projects, work items, pipelines, or code repositories unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples highlight operational capabilities such as pipeline execution and file creation without any caution about side effects, approvals, or environment impact. Example-driven agent behavior can normalize invoking these actions directly, which raises the risk of unintended CI/CD runs, repository changes, or other persistent modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script calls get_current_user and prints the returned object to stdout, which may expose user/account information. Although the operation is labeled as a demo step, there is no explicit warning that personal data will be fetched and displayed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends arbitrary tool arguments to a remote MCP endpoint via POST and also maintains an SSE connection for receiving responses, but there is no confirmation prompt or user-facing disclosure around the network transmission. Because tool arguments may contain user or system data, the absence of any warning makes this data flow non-obvious to users of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All human-facing comments and usage text are presented in Chinese, with no indication that other languages are supported or that the locale is intentionally constrained. This can violate language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · client/package.json (reported line 19)May include surrounding context.

json
"start": "node src/cli.mjs"
  },
  "dependencies": {
    "eventsource-parser": "^3.0.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language documentation and comments in Chinese, presenting the CLI usage in a single language only. Under the language/locale policy rule, forcing a specific language without user opt-in or a documented regional justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The prominent natural-language documentation in this file is entirely in Chinese and does not indicate that language selection is optional or context-specific. This can violate language/locale policy when a skill appears to impose a specific language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.