Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible Alibaba OSS deployment helper, but it asks users to expose long-lived cloud secrets and grant broad cloud permissions in ways that need careful review.

Review this before installing. Do not paste Alibaba Cloud AccessKey secrets into chat or allow screenshots of pages showing secrets. If you use this workflow, create a narrowly scoped, temporary RAM credential where possible, avoid broad DNS/CDN/OSS FullAccess unless you truly need it, rotate or revoke keys afterward, and prefer a local secure credential prompt or credential manager over plaintext chat and JSON storage.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:151
Finding

Command and JavaScript Injection Through Unsafe Parameter Interpolation

Content
View full analysis
ALIBABA_CLOUD_ACCESS_KEY_SECRET= auto-static-web deploy -d --bucket --domain --region --yes --https ``` ```bash node -e " const fs = require('fs'); const path = require('path'); const authPath = path.join(require('os').homedir(), '.ossify', 'auth.json'); const auth = JSON.parse(fs.readFileSync(authPath, 'utf8')); auth.lastDeploy = { bucket: 'BUCKET', domain: 'DOMAIN', region: 'REGION', https: true, dist: 'DIST' }; fs.writeFileSync(authPath, JSON.stringify(auth, null, 2)); " ``` ### Technical Analysis The Skill instructs the agent to substitute credentials and user-provided deployment parameters directly into shell command text and JavaScript string literals. No robust shell escaping, JavaScript escaping, or argument-array execution mechanism is specified. The deployment directory, bucket name, and domain are collected from the user. If a malicious value contains shell metacharacters, command substitutions, quotes, or JavaScript syntax, it may escape its intended argument or string context. For example, an unquoted deployment directory containing command substitution syntax could be evaluated by the shell. A single quote in a value embedded in the `node -e` snippets could terminate the JavaScript literal and introduce additional JavaScript statements. The credential format checks reduce the available character set for credentials, but equivalent validation and safe argument handling ...[truncated 1175 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:170
Finding

Unpinned Global Installation of Third-Party npm Packages

Content
View full analysis
/dev/null || npm install -g ali-oss ``` ```bash which auto-static-web # macOS/Linux where auto-static-web # Windows ``` ```text If it is not found, tell the user to run: npm install -g auto-static-web ``` ### Technical Analysis The Skill instructs the user or agent to install the latest available versions of `ali-oss` and `auto-static-web` globally from the configured npm registry. It does not pin reviewed versions, verify package integrity or provenance, use a lockfile, or isolate the packages from the global Node.js environment. npm packages may execute lifecycle scripts during installation. Consequently, a compromised package release, compromised maintainer account, malicious registry mirror, or altered local npm registry configuration could result in arbitrary code execution during installation. Using mutable package names without versions also means that the effective code can change after the Skill itself has been reviewed. No evidence establishes that the named packages are currently malicious; the vulnerability is the unsafe installation and trust model. ### Attack Path 1. The required package is absent from the global Node.js installation. 2. The Skill causes or directs the user to run an unpinned global `npm install`. 3. npm resolves the package from the user's configured registry and downloads the current mutable release. 4. A compromised package or dependency executes a lifecycle script during installation or malicious code when subsequently imported. 5. The malicious dependency gains execution with the privileges of the user performing the installation. ### Impact ...[truncated 328 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:76
Finding

Permanent Alibaba Cloud Credentials Are Granted Excessive Account-Wide Permissions

Content
View full analysis
1在列表中找到并勾选 AliyunOSSFullAccess
  • 2搜索 AliyunDNS,勾选 AliyunDNSFullAccess
  • 3搜索 AliyunCDN,勾选 AliyunCDNFullAccess
  • ``` ### Technical Analysis The Skill directs users to create a permanent RAM AccessKey and attach three full-access managed policies. These policies are substantially broader than the permissions normally required to publish one static website to one bucket and configure one domain. This design violates least privilege in two dimensions: - **Duration:** The AccessKey is permanent rather than short-lived. - **Scope:** The policies grant full access to OSS, DNS, and CDN rather than restricting access to the intended bucket, DNS record, and CDN distribution. The broad privileges amplify the consequences of any credential exposure through chat retention, local file compromise, command injection, screenshots, or third-party dependencies. ### Attack Path 1. The user follows the guide and creates a permanent RAM AccessKey. 2. The user grants `AliyunOSSFullAccess`, `AliyunDNSFullAccess`, and `AliyunCDNFullAccess`. 3. The credential is stored locally and used during deployments. 4. An attacker obtains the credential through local compromise, logs, chat history, screenshots, or another vulnerability. 5. The attacker a ...[truncated 570 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Error
    Location
    SKILL.md:84
    Finding

    Permanent Cloud Secrets Are Collected Through Chat and May Be Captured in Screenshots

    Content
    View full analysis
    4立即复制保存 AccessKey ID 和 Secret!Secret 仅显示一次。
    重要:AccessKey Secret 只在创建时显示一次!请立即复制保存。
    ``` ```html

    现在回到 Claude Code 终端,将 AccessKey ID 和 AccessKey Secret 粘贴到终端中。

    你的 AccessKey 只保存在你电脑本地(~/.ossify/auth.json),不会传输到任何外部服务器。

    ``` ### Technical Analysis The workflow explicitly asks the user to place a permanent cloud secret into conversation messages. Conversation content may be retained in terminal history, application logs, service-side transcripts, debugging records, telemetry, or support exports depending on the agent environment. The automated workflow also requests a screenshot when the newly generated AccessKey and Secret are visible. This can copy the secret into screenshot artifacts and tool traces. The documentation does not require redaction before capture. The claim that the Access ...[truncated 1277 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Rogue AgentSelf-Modification, Session Persistence
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    Findings (14)

    Missing User Warnings

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    The skill tells users to paste AccessKey ID and Secret directly into chat without a clear warning that the conversation itself becomes a sensitive channel. Chat transcripts may be retained, logged, visible to operators, or exposed through client history, making direct secret entry materially risky.

    Content

    No source excerpt is available for this finding.

    Ssd 3

    High
    Category
    Not specified by scanner
    Confidence
    100% confidence
    Finding

    This is direct collection of privileged cloud credentials through the chat channel. AccessKey secrets grant real API access, and placing them in conversation history creates a high-value disclosure point that could lead to account compromise, resource takeover, or abuse of OSS/DNS/CDN privileges.

    Content

    No source excerpt is available for this finding.

    Ssd 3

    High
    Category
    Not specified by scanner
    Confidence
    100% confidence
    Finding

    The manual flow separately requests both AccessKey ID and AccessKey Secret in chat, reproducing the same core secret-exposure problem and normalizing unsafe operator behavior. Because the skill later stores and uses the credentials for privileged deployment actions, compromise of the chat transcript can directly enable abuse.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    The security note is misleading because the skill explicitly uses the AccessKey for OSS validation and deployment, which necessarily transmits the credential to Alibaba Cloud services over the network. This can cause users to underestimate exposure and consent to handling secrets under false assumptions.

    Content

    No source excerpt is available for this finding.

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · guide/index.html (reported line 138)May include surrounding context.

    html
    <div class="step-indicator"><div class="step-circle" data-step="5">6</div><span class="step-label">完成</span></div>
        </div>
    
        <!-- Step 1: Login -->
        <div class="step-content active" data-step="0">
          <h2 class="step-title">注册/登录阿里云</h2>
          <div class="screenshot"><img src="screenshots/01-login.png" alt="阿里云登录页"></div>
    

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · guide/index.html (reported line 173)May include surrounding context.

    html
    <p class="step-text">OSS 按量付费,部署一个小网站每月费用约 ¥1-3,几乎可以忽略。</p>
        </div>
    
        <!-- Step 3: Buy Domain -->
        <div class="step-content" data-step="2">
          <h2 class="step-title">购买域名</h2>
    

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The trigger phrases are very broad and include common words like 'deploy', 'publish', '上线', and '更新凭证', increasing the chance the skill activates in unrelated conversations. Because this skill collects secrets and performs file/network actions, accidental activation raises the risk of unintended credential handling or deployment actions.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The instructional content is written as a fixed Chinese-language assistant persona and does not offer the user any language preference or opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The skill instructs creating and modifying local credential files and changing permissions without warning the user at the point of action. Users may not realize that secrets and deployment metadata are being persisted on disk, which affects confidentiality, backups, forensics, and multi-user machine exposure.

    Content

    No source excerpt is available for this finding.

    Sudo/Root Execution

    Medium
    Category
    Privilege Escalation
    Confidence
    80% confidence
    Finding

    Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

    Content

    Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

    设置文件权限(仅用户可读)

    macOS/Linux:

    chmod 600 ~/.ossify/auth.json

    Windows:

    icacls "%USERPROFILE%.ossify\auth.json" /inheritance:r /grant:r "%USERNAME%:R"

    text

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The guide broadens an OSS static-site deployment skill into unrelated domain purchase and real-name verification workflows. This increases financial, privacy, and operational exposure by steering users into buying services and submitting identity documents that are not required for the core deployment function.

    Content

    No source excerpt is available for this finding.

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    91% confidence
    Finding

    The guide tells users to create permanent AccessKeys and later paste them into the tool, with storage on disk at ~/.ossify/auth.json. Long-lived cloud credentials stored locally create significant compromise risk if the workstation, filesystem, backups, or logs are exposed, and the danger is heightened because the guide also asks for broad FullAccess permissions.

    Content

    Scanner excerpt · guide/index.html (reported line 250)May include surrounding context.

    html
    <p class="step-text">.top 域名首年约 ¥6,非常便宜。购买后需完成实名认证才能正常使用。</p>
        </div>
    
        <!-- Step 4: Create RAM User + Get AccessKey -->
        <div class="step-content" data-step="3">
          <h2 class="step-title">创建 RAM 用户并获取 AccessKey</h2>
    

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    The guide instructs users to grant AliyunDNSFullAccess and AliyunCDNFullAccess in addition to OSS access, which exceeds the stated OSS deployment scope and violates least privilege. Full DNS/CDN permissions could let the skill or any compromised local environment alter domain routing, CDN configuration, or related resources far beyond static file upload.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The document declares lang="zh-CN", and all visible instructional content is presented only in Simplified Chinese. For a general setup guide, this imposes a specific language/locale without any opt-in or alternative, which matches the language/locale policy violation category.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.