Back to skill

Security audit

alibabacloud-csas-device-health-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed read-only CSAS device health monitor, with some install and scoping cautions but no evidence of hidden, destructive, or exfiltrating behavior.

Install only if you intend to use Alibaba Cloud CSAS with a read-only profile. Review the Aliyun CLI installation source before running the curl-to-shell command, be aware that the skill may install the CSAS CLI plugin locally, and confirm the selected profile, region, device scope, scan limit, and resume-file path before allowing cloud calls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file defines invocation triggers, so vague-trigger review applies. While some listed triggers are domain-specific, "battery health" by itself is a common phrase that could match general troubleshooting or consumer-device questions unrelated to this skill, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown tells users to run a remote installer script directly without any guidance for authenticity verification, pinning, or post-download review. That creates a software supply-chain risk and normalizes unsafe operational practice, especially because documentation is likely to be followed verbatim by users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs users to execute a remote shell script directly from the network via curl piped to bash, which bypasses normal review and integrity checks and can lead to arbitrary code execution if the hosting endpoint, delivery path, or script content is compromised. In a read-only monitoring skill, this installation method is not necessary to the core diagnostic function and expands risk well beyond the stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest explicitly states the skill 'does not ... check client versions'. However, the list-devices command accepts AppVersion as a sort key and passes it to the CSAS list-user-devices API. Even though the returned JSON omits the version field, this still implements behavior based on client version metadata that the description disclaims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest narrows the skill to health and risk monitoring and specifically says it 'does not count inventory'. The list-devices path calls list-user-devices and returns fleet_total from TotalNum plus a device enumeration payload, which is an inventory-counting/listing capability beyond the stated scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger list should be specific enough to avoid collisions with everyday support language. "endpoint online status" is broader than the skill's Alibaba Cloud CSAS scope and may ambiguously match other endpoint-management or connectivity requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as performing read-only device health and risk monitoring, but this guide states the script will install the CSAS CLI plugin if absent. Although local-only, automatic dependency installation is still a system-modifying capability that is not part of the core health-monitoring intent described in the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The comment says plugin setup is deferred so '--help and invalid-input paths do not change the caller's CLI installation'. However, command handlers invoke csas() after argument parsing, and operations like list-devices can still trigger plugin installation as part of normal execution. The documentation minimizes or obscures that local installation side effect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script automatically installs the aliyun-cli-csas plugin on the local system when missing, which modifies the caller's environment and executes newly fetched code. In a supposedly read-only monitoring skill, this creates a supply-chain and unexpected local state-change risk, especially if plugin sources or trust policy are not explicitly controlled.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.