DataWorks Open API

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requests, scripts, and instructions are coherent with its stated purpose (managing Alibaba Cloud DataWorks via runtime API discovery and official SDKs); nothing requests unrelated credentials or installs arbitrary code from unknown hosts.

This skill appears to do what it says: discover DataWorks APIs and call them using official SDKs. Before installing: (1) Only provide Alibaba Cloud credentials you trust — prefer a local credentials URI or short-lived STS tokens and avoid giving long-lived production AK/SK; (2) Limit the provided credentials to least privilege (DataWorks-only or scoped roles); (3) Note the included scripts will write files under output/dataworks-open-api and may call curl as a fallback; they also try an unverified SSL context as a last resort (this is for robustness but weakens TLS verification if triggered). If you plan to run the MCP Server integration, review its configuration and environment vars carefully. If you need higher assurance, run the skill in an isolated environment and inspect the output files and network calls during initial use.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal