Alibabacloud Migration Mas Solution

Security checks across malware telemetry and agentic risk

Overview

This appears to be a cloud migration guidance skill with a documentation safety gap, not evidence of hidden or malicious behavior.

Before using this skill for real migrations, require a backup and rollback plan, least-privilege temporary credentials, encrypted transfer/storage, integrity checks, maintenance-window planning, and post-migration validation. Do not run production migrations directly from the mapping table without a reviewed runbook.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The file provides concrete migration methods such as DTS, Redis-Shake, MirrorMaker, snapshot, backup/restore, export/import, and rsync across many data services, but it includes no safety guidance about credential handling, encryption, access scoping, integrity verification, rollback, or the risk of data loss and service disruption. In a cloud migration skill, users are likely to act on these instructions directly, so the omission can lead to unsafe transfers of sensitive data or damaging production changes even though the content is not overtly malicious.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal