Alibabacloud Network Alb Http To Https
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, instructions, and required permissions align with its stated purpose of configuring HTTP→HTTPS redirects on Alibaba Cloud ALB and do not request unrelated access or implement hidden exfiltration.
This skill appears coherent and implements ALB HTTP→HTTPS redirect workflows as described, but before running: 1) Ensure you have a separate test ALB or backup—the skill performs write operations (listeners, rules, cert uploads). 2) Grant the minimal RAM permissions documented in references/ram-policies.md (avoid using wildcard alb:*/cas:*). 3) Review the scripts yourself (they are included) and run with --dry-run where available. 4) If you must install the Aliyun CLI, avoid blind curl | bash piping; verify the download and signature from the official source. 5) Be aware the skill requires your Alibaba Cloud credentials to be configured locally (aliyun configure or env vars); do not paste credentials into the chat and follow the SKILL.md guidance to avoid printing secrets. If you want higher assurance, run the scripts in a constrained environment or sandbox first.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
