Back to skill

Security audit

DashScope LLM

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed DashScope chat CLI that sends a user-provided prompt to Alibaba Cloud using an environment API key.

Install only if you intend to send prompts to Alibaba Cloud DashScope. Treat anything passed in --message as leaving your machine, and do not include secrets, regulated data, or proprietary text unless that use is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents that it reads DASHSCOPE_API_KEY from the environment, but it does not declare any explicit tool scope or permissions metadata. This creates an authorization/transparency gap: users and hosting systems may not be clearly informed that the skill accesses secrets from the environment, increasing the chance of unintended secret exposure or unsafe execution assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied prompts to DashScope's third-party API, but the description does not prominently warn users that their input leaves the local environment. This can lead to accidental disclosure of sensitive data, credentials, internal prompts, or proprietary text to an external service under the mistaken belief that the processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends args.message to a remote API via client.chat.completions.create(...), which transmits user-provided content over the network. There is no confirmation prompt, warning comment, docstring, or print/log statement informing the user that their message will be sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file presents key descriptive content and the default example prompt in Chinese while the operational instructions are in English, but it does not tell users they may choose their preferred language. This creates an implicit locale preference without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code reads DASHSCOPE_API_KEY from the environment to authenticate with an external service, but the file provides no comment, docstring, or user-facing notice about this credential use. For safety review purposes, accessing sensitive environment variables should include some disclosure unless clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.