Security audit
alibabacloud-ecs-ops
Security checks across malware telemetry and agentic risk
Overview
This is a disclosed Alibaba Cloud ECS operations plugin, but it should be reviewed because its high-impact cloud authority is paired with broader MCP access than the stated safety scoping shows.
Before installing, review the MCP tool exposure and run it only with a least-privilege Alibaba Cloud RAM role or test account. Treat destructive or chargeable operations as requiring explicit human confirmation, and disable ALIBABACLOUD_TELEMETRY or ALIBABACLOUD_TRACE if the default telemetry or local audit traces are not acceptable for your environment.
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
65/65 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
