Back to skill

Security audit

alibabacloud-dts-doc-parse

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a disclosed Alibaba Cloud document parser, but it also performs automatic CLI/skill updates and uses remote installer scripts, which deserve review before installation.

Install only if you are comfortable with Alibaba Cloud DTS-AI receiving the documents you explicitly ask it to parse, with dtscli storing its API key and recovery state under your home directory, and with the DTS CLI/skills update mechanism changing installed DTS skill files. Review or replace the remote installer process if your environment requires signed packages or checksum verification, and consider disabling automatic DTS skill updates if you need pinned behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/dts-ai-authentication.md (reported line 8)May include surrounding context.

md
Resolve the API key in this order:

1. The `DTS_AI_API_KEY` environment variable in the current process.
2. `~/.aliyun-dts/dts-ai/credentials.json`.

Never read or modify a shell startup file. Never print, log, or separately persist the decoded API key.

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The documented installation flow pipes a remotely fetched script directly into Bash, which is a classic unsafe pattern because it executes network-supplied code without an inspection or integrity verification step. Even though the document adds authorization and platform-compatibility guidance, a compromised host, bucket, TLS interception point, or accidental content change could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · references/runtime-platforms.md (reported line 12)May include surrounding context.

After installation authorization, use the Bash installer on macOS/Linux:

bash
curl --proto '=https' --proto-redir '=https' -fsSL https://aliyun-dts-cli.oss-cn-hangzhou.aliyuncs.com/install.sh | bash -s -- --yes

Use --yes only for a non-interactive installation the user has already authorized. Do not run the installer before that authorization exists.

Self-Modification

High
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs the agent to run dtscli skills ensure, which can update both the CLI and installed skills from a remote distribution source during normal execution. This is effectively self-modifying behavior: it changes the toolchain and skill code the agent relies on at runtime, expanding the trust boundary to remote update infrastructure and creating a supply-chain risk if that source, PATH resolution, or package metadata is compromised.

Content

Scanner excerpt · references/skills-updates.md (reported line 17)May include surrounding context.

md
## Cache and scope

- `skills ensure` and `skills install` both update the CLI first, then use the **current CLI** to install or update Skills. The two rolling 24-hour caches are separate: CLI under `~/.aliyun-dts/updates/cli/`, Skills under `~/.aliyun-dts/updates/skills/`, both respecting `DTS_STATE_ROOT`. Do not delete the cache or repeatedly retry to bypass this limit.
- Installations with valid package identity metadata participate by default. The CLI checks only DTS Skills already installed in the selected directory and automatically reads each package's name, version, and minimum CLI; it does not add other skills. A package leaf that is a symlink is resolved and checked against the real directory; the link target is never replaced. Catalog checks use this CLI's Skills source. Directories without valid package identity metadata stay `unmanaged`. Reinstall an old package once from the joint release to identify it.
- The CLI automatically fetches the latest release manifest from its own distribution source. A newer CLI is installed first, then the new `dtscli` continues. Each Skill's release manifest is fetched from this CLI's Skills source, one manifest per package. Caches are separate for each Skill source; Agents share the cache for the same Skill. Test and production caches are isolated by source.
- Updates install a newer catalog version only. Same-version content changes are not replaced. If the current CLI is still below a package's minimum, keep the old package (`dependency_failed`). Never automatically downgrade.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
## Capabilities and supported formats

Use `dtscli doc parse` to parse supported local files into Markdown and deliver the final files to the user. Cloud jobs and their recovery mechanism are internal implementation details; in the normal workflow, never ask the user to inspect, select, or resume a job.

Parse readable, non-empty local files with these extensions: `pdf`, `docx`, `pptx`, `png`, `jpg`, and `jpeg`.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction says to use --language zh for a Chinese conversation and --language en otherwise, which imposes a locale/language behavior by default rather than offering the user a choice. Under the policy, language constraints should be opt-in or clearly justified as region-specific; this line does not present the choice to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.