Alibabacloud Cfw Exposure Detection
PassAudited by VirusTotal on Apr 28, 2026.
Findings (1)
The skill bundle is a legitimate security auditing tool designed to analyze Alibaba Cloud public network exposure using the official Aliyun CLI. It follows a structured, read-only workflow (Steps 1–9) to query firewall statistics, exposed IPs/ports, and vulnerability data via the 'cloudfw' plugin. The instructions in SKILL.md include strong safeguards against credential theft (explicitly forbidding the printing of AK/SK), mandate data desensitization (masking IPs and IDs), and restrict network access to official Alibaba Cloud endpoints. While it contains a 'curl|bash' command for CLI installation, it points to the official Alibaba Cloud CDN (alicdn.com), and the forceful prompt instructions are clearly intended to ensure the agent completes the complex multi-step audit without interruption.
