Back to skill

Security audit

Alibaba Cloud STS

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Alibaba Cloud STS purpose, but it allows temporary cloud credentials to be issued without clear user confirmation or secret-handling safeguards.

Install only if you are comfortable letting the agent use your OOMOL-connected Alibaba Cloud STS account. Require confirmation before any action that returns temporary credentials, avoid pasting those credentials into logs or chat unnecessarily, and verify the oo CLI installer through OOMOL's official installation documentation before running remote install commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The documentation instructs users to execute a remote install script directly via curl ... | bash, which gives the remote server immediate code execution on the host without prior integrity verification. If the install endpoint, transport, or hosting pipeline is compromised, this becomes a straightforward supply-chain execution vector.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that untagged actions are reads and safe to run directly, but get_federated_credentials issues fresh temporary credentials rather than merely reading data. That misclassification can cause an agent to run a credential-minting operation without heightened confirmation, increasing the risk of unintended secret generation and disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.