Back to skill

Security audit

Alibabacloud Cleversee Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Alibaba Cloud web-search helper with expected credential setup steps, but users should be aware it can configure local cloud profiles.

Install this only if you want Codex to use Alibaba Cloud CleverSee for web search. Be careful with credential setup: prefer existing scoped profiles, confirm every profile or auth parameter before use, and do not expose access keys in chat or logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest and title frame the skill as a web-search capability, yet the file documents and instructs use of `cleversee auth set` and `cleversee auth switch`, which modify authentication configuration rather than performing search. Credential management is broader than an obvious implementation detail of running a search and materially expands the skill's operational scope.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
`cleversee web-search` may be read-only, but the same document includes `cleversee auth set` workflows that write or alter credential/profile state. Saying the skill is a read-only operation without clearly scoping that statement to search behavior creates an intent-level contradiction in the documentation.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The listed triggers include generic phrases such as "web search", "查资料", and "实时信息", which can appear in normal user requests unrelated to explicitly invoking this skill. The file does not provide exclusion conditions or negative examples to clarify when the skill should or should not activate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.