DataWorks Open API
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requests, scripts, and instructions are coherent with its stated purpose (managing Alibaba Cloud DataWorks via runtime API discovery and official SDKs); nothing requests unrelated credentials or installs arbitrary code from unknown hosts.
This skill appears to do what it says: discover DataWorks APIs and call them using official SDKs. Before installing: (1) Only provide Alibaba Cloud credentials you trust — prefer a local credentials URI or short-lived STS tokens and avoid giving long-lived production AK/SK; (2) Limit the provided credentials to least privilege (DataWorks-only or scoped roles); (3) Note the included scripts will write files under output/dataworks-open-api and may call curl as a fallback; they also try an unverified SSL context as a last resort (this is for robustness but weakens TLS verification if triggered). If you plan to run the MCP Server integration, review its configuration and environment vars carefully. If you need higher assurance, run the skill in an isolated environment and inspect the output files and network calls during initial use.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
