Back to skill

Security audit

alibabacloud-cfw-vpc-firewall-cen-basic-manage

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped Alibaba Cloud firewall operations helper that can change production firewall routing, but its artifacts disclose the impact and require explicit confirmation for the riskiest actions.

Install this only for operators who are allowed to manage Alibaba Cloud Firewall CEN Basic VPC firewalls. Review the RAM policy first, use least-privilege credentials, verify CLI/plugin installation sources, and do not approve switch or removal operations until the agent has shown the exact impact and target resources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (43)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
bash scripts/validate-cli.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
bash scripts/validate-cli.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
bash scripts/validate-cli.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
bash scripts/validate-cli.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
`references/api-errors.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 492)May include surrounding context.

md
`references/api-errors.md`.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 470)May include surrounding context.

md
#    and check LocalVpc.TransitRouterType == "Basic" per row

# ❌ lowercase value: the filter is silently dropped and every slot in the
#    account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic

# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 38)May include surrounding context.

md
#    and check LocalVpc.TransitRouterType == "Basic" per row

# ❌ lowercase value: the filter is silently dropped and every slot in the
#    account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic

# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/workflow.md (reported line 428)May include surrounding context.

md
#    and check LocalVpc.TransitRouterType == "Basic" per row

# ❌ lowercase value: the filter is silently dropped and every slot in the
#    account is returned, HTTP 200, no warning
aliyun cloudfw describe-vpc-firewall-cen-list --transit-router-type basic

# ❌ relying on AllowConfiguration to tell editions apart - it answers whether the

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

A self-update capability introduces self-modification of a security-relevant tool, which can change executable behavior outside normal change-control and reproducibility expectations. In an agent ecosystem, encouraging automatic or ad hoc upgrades may undermine version pinning, review, and supply-chain assurance.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 82)May include surrounding context.

aliyun version

text

### Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The explicit 'aliyun upgrade' command modifies the installed CLI in place, which can alter behavior and dependencies without the skill author validating compatibility or integrity at that moment. This is risky for operational reproducibility and can expand exposure if the update channel is ever abused.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 84)May include surrounding context.

Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

bash
aliyun upgrade

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/cfw_cen_basic.py (reported line 1605)May include surrounding context.

python
"holds values because it reflects the business VPC's own routing."
            )
        # Reaching notconfigured is necessary but not sufficient. A slot can report the
        # reset state while still holding an ENI, and calling that success would tell
        # the caller traffic had stopped being diverted when it had not.
        payload["ok"] = reset_ok
        if last_in_region:

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/cfw_cen_basic.py (reported line 1614)May include surrounding context.

python
"holds values because it reflects the business VPC's own routing."
            )
        # Reaching notconfigured is necessary but not sufficient. A slot can report the
        # reset state while still holding an ENI, and calling that success would tell
        # the caller traffic had stopped being diverted when it had not.
        payload["ok"] = reset_ok
        if last_in_region:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.

Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.

Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/cfw_cen_basic.py (reported line 1120)May include surrounding context.

python
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.

Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/cfw_cen_basic.py (reported line 1469)May include surrounding context.

python
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.

Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
| Open or close diversion | `list` to resolve a name, explain the impact, wait for a new explicit user confirmation, then run `switch ... --yes` |
| Rename | `list` to resolve a name, then run `rename`; no extra consent is required |
| Remove access | `list` to resolve a name and determine blast radius, explain it, wait for a new explicit user confirmation, then run `remove ... --yes` |
A firewall name or an instruction such as "pick the first slot" is enough for read-only discovery. Never ask the user for an id that `list` can resolve. The original request to change state is not the separate consent required for `switch`, `remove`, or attach-with-open: do not pass `--yes` until the user replies after seeing the operation-specific impact. For a removal, stop after the impact explanation and wait for a second user message that explicitly confirms the named firewall; a dry run, the original request, or the Agent's own summary is never that confirmation. A no-op needs no consent.

Full parameter sets, the state machine and the polling contracts are in
`references/workflow.md`. Error codes and what to do about them are in

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

md
all of them and supply the CIDR and zone pair again. Pass `--yes` only after the user
has agreed.

It skips a `notconfigured` slot without asking for confirmation, because that slot is
already removed and the call would only return `-360134`. It waits for a transient
state to settle. It warns when the slot is `opened`, because closing diversion first is
the verified path; removing straight from `opened` needs `--force-open` and is

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is a broad Alibaba Cloud CLI installation and authentication guide, not a narrowly scoped reference for managing Cloud Firewall CEN Basic VPC firewalls. In an agent skill, this over-broad reference increases the reachable action surface by teaching credential setup, multi-service usage, and generic cloud administration patterns beyond the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation command pipes a network-fetched script directly into a shell, which executes remote code without independent integrity verification or user review. In a security-sensitive agent skill, this is particularly dangerous because it normalizes an unsafe supply-chain practice that could lead to arbitrary code execution if the distribution endpoint or path is compromised.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 48)May include surrounding context.

x86_64

bash
wget --connect-timeout=10 --read-timeout=120 --tries=3 -qO- https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xz
sudo mv aliyun /usr/local/bin/

ARM64

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 54)May include surrounding context.

x86_64

bash
wget --connect-timeout=10 --read-timeout=120 --tries=3 -qO- https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xz
sudo mv aliyun /usr/local/bin/

ARM64

Static analysis

No suspicious patterns detected.