Back to skill

Security audit

alibabacloud-domain

Security checks for vulnerabilities and agentic risk

Overview

This skill is a sensitive Alibaba Cloud domain-management runbook with strong fail-closed controls; I found no deception or exfiltration, though its bundled manifest appears incomplete and may block use until fixed.

Install this only if you want an agent to operate Alibaba Cloud DomainCLI for domain, DNS, ICP, and Wan Xiao Zhi website tasks. Keep cloud credentials scoped, review every preview carefully, and do not approve payments, DNS changes, publication, deletion, or account-affecting changes unless the exact target and impact match your intent. The publisher should fix references/manifest.json to include the required skill name before relying on the skill operationally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises broad domain, ICP, DNS, and website-management functionality, but the visible content is mostly policy and orchestration instructions rather than implementable task logic. This mismatch can mislead operators or higher-level agents into trusting the skill to perform or validate sensitive operations that it cannot actually carry out, increasing the chance of unsafe fallback behavior, incorrect completion claims, or improper handoff during cloud changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope even though it clearly expects file reads and shell command execution. That creates an authorization ambiguity where a host agent may grant broader capabilities than intended or users may be unable to reason about what the skill can access and execute. In a security-sensitive skill that invokes CLI operations against cloud resources, undeclared execution surface is a real risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
1. Freeze an intent envelope before the first operational call: selected profile and configuration store, product namespace, exact user-supplied target identifiers, requested action, before/after values, and any price, duration, payment route, plan ID, or publication channel. Readbacks may resolve a missing identifier, but they must never replace an identifier the user supplied. If the exact target is missing, inaccessible, externally managed, or ambiguous, stop and ask for the correct target or account.
2. Advance only on structured DomainCLI evidence for the same intent envelope. A command string in the response, an attempted invocation, an OAuth callback, an error message that mentions an expected field, or a different resource's successful readback is not success.
3. Treat authentication unavailable, profile conflict, target mismatch, unsupported friendly leaf, failed or incomplete preview, missing fresh confirmation, and ambiguous write outcome as terminal for the current step. A non-retryable internal error is also terminal; a generic `next_action` does not override `retryable=false`. Return the confirmed state and the next safe DomainCLI command; do not switch credentials, targets, namespaces, or execution surfaces to keep going, including for extra discovery or diagnosis after a failure.
4. High-risk and financial confirmation is valid only after a successful current preview exposes the exact impact. Earlier broad instructions such as “执行到底” are not post-preview approval. If the runtime cannot collect a reply, present the preview and stop.

Use [Safety and confirmation](references/safety.md) for the evidence and confirmation rules, [Authentication](references/authentication.md) for OAuth terminal states, and [Error recovery](references/error-recovery.md) for the only permitted recovery paths.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/ram-policies.md (reported line 14)May include surrounding context.

md
- `domain:QueryDomainList`
- `domain:QueryDomainByDomainName`
- `domain:QueryAdvancedDomainList`
- `domain:QueryDomainGroupList`
- `domain:QueryContactInfo`
- `domain:QueryRegistrantProfiles`
- `domain:QueryRegistrantProfileRealNameVerificationInfo`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/safety.md (reported line 58)May include surrounding context.

md
- A fixed-price marketplace listing is a domain transaction and must not be presented as a registration price.
- Direct account payment can use eligible available credit only when DomainCLI explicitly offers it. It still requires the CLI's payment confirmation, amount check when present, and price-change acknowledgement when required.
- Never claim a browser-opened checkout is paid or an accepted asynchronous order is completed.
- Never auto-approve a payment because the user previously approved another domain or another stage.

## Secrets and private data

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/website.md (reported line 17)May include surrounding context.

md
6. Read `project --operation show` for the requested `bizId`, then use `aliyun domain wxz deploy --operation publish` to preview publication for that same project. Require structured preview success, obtain user confirmation, then rerun that same leaf with `--confirm=true`.
7. Follow deployment with `deploy --operation status`; use `deploy --operation history` for prior versions and `deploy --operation rollback` only after a separate rollback confirmation. Observe the bounded wait contract; manual input, review, or a pending deployment is a handoff, not an indefinite polling loop.

No stage automatically performs the next one. Inspect each leaf's `--help` for the exact IDs and flags.

## Command families

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/website.md (reported line 60)May include surrounding context.

md
- Deleting projects, directories, plugins, or other persistent resources.
- Replacing generated code or material state.

Never auto-confirm `--confirm=true`. Preserve exact `bizId`, domain, conversation ID, chat ID, channel, and requested operation between preview and execution. If state changes, re-preview.

If authentication fails, the requested project is not found, the preview fails, or the friendly `aliyun domain wxz` leaf is unavailable, stop that stage. Do not choose another project, call generated WebsiteBuild actions, or publish through raw OpenAPI, SDK, HTTP, or console automation.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/eval_domain_preflight.py (reported line 72)May include surrounding context.

python
result.add_argument("--profile", help="Preserve this exact parent CLI profile selector; not a credential value.")
    result.add_argument("--config-path", help="Preserve this exact parent CLI configuration-store selector; file is not read here.")
    result.add_argument("--check-cloud", action="store_true", help="Explicitly allow read-only cloud identity and supplied exact-target checks.")
    result.add_argument("--fixture-file", help="Already delivered absolute single-link read-fixtures.json; only the fixed non-secret locator registry is allowed. Reject symlinks/hardlinks, non-regular files, foreign owners and group/world-writable files. Does not create the file or authorize cloud access.")
    result.add_argument("--domain-key", choices=DOMAIN_FIXTURE_KEYS, help="Explicitly select this domain locator field; with an explicit --domain the default comparison key is asset_domain. No registrar check is inferred merely from other fields in the file.")
    result.add_argument("--dns-zone-from-fixture", action="store_true", help="Explicitly select dns_zone from --fixture-file. DNS-only checks do not request registrar ownership reads for unrelated asset_domain locators.")
    result.add_argument("--require-ready", action="store_true", help="Functional runner gate: exit 0 only for status=ready with verified cloud identity and every requested exact-target fixture ready. Without --check-cloud, local checks remain local_only and exit 1.")

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The example for aliyun domain ask uses a Chinese-language question literal ("域名过期后多久进入赎回期?"). While this is only an example, the document does not indicate that users may choose their own language or that the skill is intentionally limited to Chinese-language operation, which can create an implicit language/locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.