Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md bash scripts/validate-cli.sh
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a scoped Alibaba Cloud firewall operations helper that can change production firewall routing, but its artifacts disclose the impact and require explicit confirmation for the riskiest actions.
Install this only for operators who are allowed to manage Alibaba Cloud Firewall CEN Basic VPC firewalls. Review the RAM policy first, use least-privilege credentials, verify CLI/plugin installation sources, and do not approve switch or removal operations until the agent has shown the exact impact and target resources.
Referenced artifact was not completely inspected
bash scripts/validate-cli.sh
Referenced artifact was not completely inspected
bash scripts/validate-cli.sh
Referenced artifact was not completely inspected
bash scripts/validate-cli.sh
Referenced artifact was not completely inspected
bash scripts/validate-cli.sh
Referenced artifact was not completely inspected
`references/api-errors.md`.
Referenced artifact was not completely inspected
`references/api-errors.md`.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
# and check LocalVpc.TransitRouterType == "Basic" per row
# ❌ lowercase value: the filter is silently dropped and every slot in the
# account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic
# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
# and check LocalVpc.TransitRouterType == "Basic" per row
# ❌ lowercase value: the filter is silently dropped and every slot in the
# account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic
# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
# and check LocalVpc.TransitRouterType == "Basic" per row
# ❌ lowercase value: the filter is silently dropped and every slot in the
# account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic
# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the
A self-update capability introduces self-modification of a security-relevant tool, which can change executable behavior outside normal change-control and reproducibility expectations. In an agent ecosystem, encouraging automatic or ad hoc upgrades may undermine version pinning, review, and supply-chain assurance.
aliyun version
### Self-Update (CLI >= 3.3.5)
Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:
The explicit 'aliyun upgrade' command modifies the installed CLI in place, which can alter behavior and dependencies without the skill author validating compatibility or integrity at that moment. This is risky for operational reproducibility and can expand exposure if the update channel is ever abused.
Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:
aliyun upgrade
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
"holds values because it reflects the business VPC's own routing."
)
# Reaching notconfigured is necessary but not sufficient. A slot can report the
# reset state while still holding an ENI, and calling that success would tell
# the caller traffic had stopped being diverted when it had not.
payload["ok"] = reset_ok
if last_in_region:
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
"holds values because it reflects the business VPC's own routing."
)
# Reaching notconfigured is necessary but not sufficient. A slot can report the
# reset state while still holding an ENI, and calling that success would tell
# the caller traffic had stopped being diverted when it had not.
payload["ok"] = reset_ok
if last_in_region:
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.
Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.
Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.
Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.
Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.
Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
all of them and supply the CIDR and zone pair again. Pass `--yes` only after the user
has agreed.
It skips a `notconfigured` slot without asking for confirmation, because that slot is
already removed and the call would only return `-360134`. It waits for a transient
state to settle. It warns when the slot is `opened`, because closing diversion first is
the verified path; removing straight from `opened` needs `--force-open` and is
The file is a broad Alibaba Cloud CLI installation and authentication guide, not a narrowly scoped reference for managing Cloud Firewall CEN Basic VPC firewalls. In an agent skill, this over-broad reference increases the reachable action surface by teaching credential setup, multi-service usage, and generic cloud administration patterns beyond the declared purpose.
The installation command pipes a network-fetched script directly into a shell, which executes remote code without independent integrity verification or user review. In a security-sensitive agent skill, this is particularly dangerous because it normalizes an unsafe supply-chain practice that could lead to arbitrary code execution if the distribution endpoint or path is compromised.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
x86_64
wget --connect-timeout=10 --read-timeout=120 --tries=3 -qO- https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xz
sudo mv aliyun /usr/local/bin/
ARM64
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
x86_64
wget --connect-timeout=10 --read-timeout=120 --tries=3 -qO- https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xz
sudo mv aliyun /usr/local/bin/
ARM64
No suspicious patterns detected.