Back to skill

Security audit

alibabacloud-dts-job-manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Alibaba Cloud DTS manager, but it can install or update tooling, create billable cloud resources, and store database credentials locally in ways users should review carefully before installing.

Install only if you are comfortable with a skill that can manage billable DTS resources, install or update local Alibaba Cloud tooling, and store database credentials locally as reversible Base64. Use least-privilege Alibaba Cloud permissions where possible, consider setting DTS_SKILLS_AUTO_UPDATE=0 if automatic skill updates are not acceptable, and avoid using this workflow for PostgreSQL or MongoDB links unless the documented non-encrypted connection requirement is acceptable in your network environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (31)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The document instructs users to download and immediately execute a remote shell script via curl ... | bash, which bypasses any opportunity to inspect, pin, or verify the installer before execution. If the hosting bucket, CDN path, TLS trust chain, or upstream release process were compromised, this would result in arbitrary code execution on the user's machine with the user's privileges.

Content

Scanner excerpt · references/runtime-platforms.md (reported line 12)May include surrounding context.

After installation authorization, use the Bash installer on macOS/Linux:

bash
curl --proto '=https' --proto-redir '=https' -fsSL https://aliyun-dts-cli.oss-cn-hangzhou.aliyuncs.com/install.sh | bash -s -- --yes

Use --yes only for a non-interactive installation the user has already authorized. Do not run the installer before that authorization exists.

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill instructs the agent to run a command that can update both the CLI and installed skills from a remote distribution source during a live session. This is a real self-modification risk because it changes the toolchain and skill contents the agent relies on, potentially invalidating the current trust boundary and enabling execution under newly fetched code or instructions.

Content

Scanner excerpt · references/skills-updates.md (reported line 17)May include surrounding context.

md
## Cache and scope

- `skills ensure` and `skills install` both update the CLI first, then use the **current CLI** to install or update Skills. The two rolling 24-hour caches are separate: CLI under `~/.aliyun-dts/updates/cli/`, Skills under `~/.aliyun-dts/updates/skills/`, both respecting `DTS_STATE_ROOT`. Do not delete the cache or repeatedly retry to bypass this limit.
- Installations with valid package identity metadata participate by default. The CLI checks only DTS Skills already installed in the selected directory and automatically reads each package's name, version, and minimum CLI; it does not add other skills. A package leaf that is a symlink is resolved and checked against the real directory; the link target is never replaced. Catalog checks use this CLI's Skills source. Directories without valid package identity metadata stay `unmanaged`. Reinstall an old package once from the joint release to identify it.
- The CLI automatically fetches the latest release manifest from its own distribution source. A newer CLI is installed first, then the new `dtscli` continues. Each Skill's release manifest is fetched from this CLI's Skills source, one manifest per package. Caches are separate for each Skill source; Agents share the cache for the same Skill. Test and production caches are isolated by source.
- Updates install a newer catalog version only. Same-version content changes are not replaced. If the current CLI is still below a package's minimum, keep the old package (`dependency_failed`). Never automatically downgrade.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description/invocation text is broader than the operational scope defined later in the skill, including generic migration and "sync data from one database to another" requests even though migration, cross-account work, reverse sync, and unsupported engines are explicitly out of scope. This can cause the agent to select the skill for requests it is not designed to handle, increasing the chance of unsafe command execution attempts, mis-scoped actions, or user confusion around destructive/billable operations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The instruction to install missing DTS/Alibaba Cloud CLI dependencies without asking the user authorizes a host-modifying action based solely on error output. This creates a clear autonomy boundary violation: the skill is not just reading cloud state but changing the execution environment, potentially conflicting with enterprise controls or exposing users to package trust risks.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

Every operation runs through dtscli, which must be on PATH. macOS, Linux, and Windows are supported. When the shell reports dtscli: command not found, read platform installation and command execution to select the installer, paths, and shell syntax for the actual host. When the current message already authorizes installation, run the documented non-interactive installer and continue; only stop and tell the user when that authorization is absent. Never fall back to another way of calling DTS.

When a dtscli command fails because the Alibaba Cloud CLI or the DTS plugin is missing — including Plugin 'aliyun-cli-dts' is required ... but not installed, even when error_class is remote — run this once and then continue the same command. Do not ask the user to authorize it, and do not add --update:

bash
dtscli job deps install --yes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs automatic installation of dependencies (dtscli job deps install --yes) without a user-facing warning or approval at the point of execution. Installing software changes the local environment and can introduce supply-chain or policy risks, especially because it is triggered automatically in response to runtime errors rather than through a clearly consented setup step.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- Never accept or handle a secret, credential, token, or authorization code in chat. Follow [setup](references/setup.md) for authentication and [database credentials and connection tests](references/credentials-and-security.md) for database credentials.
- Before every management operation, show the redacted target, key parameters, action, and billing or lifecycle impact, then obtain explicit confirmation. A change to the plan, parameters, or action requires new confirmation.
- When the same user message names the instances, databases or tables, and job name, and explicitly approves purchasing that unchanged plan, run `dtscli job create execute --attempt-id <attempt-id> --yes` once. Do not copy `confirmation_sha256` to the user. A changed plan requires a new confirmation.
- When the same user message names the job region and the job name (or job ID) and explicitly approves suspending, starting, or renaming that unchanged target, show the review and run that one operation once without asking again. That authorization covers only that job and that operation: a change to the target, direction, or operation requires new confirmation, and it never carries over to another job or another operation.
- Do not retry a management operation before verifying the previous outcome. When a purchase result is ambiguous, stop, ask the user to check the console, and never retry `execute`.
- Execute only a call that matches the user's request and appears in the [API allowlist](references/api-allowlist.md).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 66)May include surrounding context.

md
- Never accept or handle a secret, credential, token, or authorization code in chat. Follow [setup](references/setup.md) for authentication and [database credentials and connection tests](references/credentials-and-security.md) for database credentials.
- Before every management operation, show the redacted target, key parameters, action, and billing or lifecycle impact, then obtain explicit confirmation. A change to the plan, parameters, or action requires new confirmation.
- When the same user message names the instances, databases or tables, and job name, and explicitly approves purchasing that unchanged plan, run `dtscli job create execute --attempt-id <attempt-id> --yes` once. Do not copy `confirmation_sha256` to the user. A changed plan requires a new confirmation.
- When the same user message names the job region and the job name (or job ID) and explicitly approves suspending, starting, or renaming that unchanged target, show the review and run that one operation once without asking again. That authorization covers only that job and that operation: a change to the target, direction, or operation requires new confirmation, and it never carries over to another job or another operation.
- Do not retry a management operation before verifying the previous outcome. When a purchase result is ambiguous, stop, ask the user to check the console, and never retry `execute`.
- Execute only a call that matches the user's request and appears in the [API allowlist](references/api-allowlist.md).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill allows automatic re-execution of a previously approved create operation after installing missing CLI/plugin components, without re-confirming at the moment the environment has changed. Because execute can finalize a billable resource purchase or start configuration on an already purchased instance, rerunning it after an implicit environment modification increases the risk of unintended cloud-side changes.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

dtscli job create execute --attempt-id --yes

text

Do not copy `confirmation_sha256`. When `outcome` is `indeterminate`, or `failed` with `resource_effect` `UNKNOWN`, stop and never retry `execute`; if a job ID is present, run `dtscli job get --job-id <job-id> --region <region-id>`, otherwise ask the user to check the console. When `outcome` is `failed` with `resource_effect` `NONE` (nothing was created) or `INSTANCE_PURCHASED` (the instance exists and is billing), determine the cause. If the only cause is a missing Alibaba Cloud CLI or DTS plugin, install it as described under Runtime and execute once more on the same `attempt_id` without asking again. For any other cause, obtain the user's confirmation again, and then execute once more on the same `attempt_id`: the purchased instance is reused for configuration and start, and a second instance is never bought.

7. After a successful create, follow `next_step` for the precheck, then `job get`. Do not wait for delay 0; a `CHECKING` precheck is not a failure — query it again as described in [job status · precheck](references/job-status.md#precheck).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The skill permits running dtscli upgrade automatically when a capability is missing, provided the current message broadly authorizes installing or upgrading runtime dependencies. An upgrade is a host and toolchain modification with behavioral consequences, and performing it automatically can alter future command semantics or trust assumptions without a dedicated approval checkpoint.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

If a job ID is known, run dtscli job get --job-id <job-id> --region <region-id>. When only a name is known, run dtscli job list --region <region-id> --job-name <job-name> and compare complete names case-sensitively on this page. Stop when there are zero or multiple exact matches. After one match, run job get or dtscli job precheck --job-id <job-id> --region <region-id>. Add --with-db-list when the user asks for the synchronized objects, and report the structured db_list mapping and counts. Interpret the raw status. Report an unknown value as-is and stop before any write.

When configuring a job and only an instance name is known, use dtscli job instances to resolve the instance ID; do not treat it as job list. First confirm that the capabilities from this session's dtscli version --json include job.instances. When they do not and the current user message already authorizes installing or upgrading the runtime dependencies, run dtscli upgrade once, rerun dtscli version --json, and continue once the capability appears; do not ask the user about it. Stop and tell the user to upgrade dtscli only when the capability is still missing after the upgrade or that authorization is absent. Pass the user-given instance name as --instance-id. Search the source and destination separately: use --usage-type src to resolve the source and --usage-type dest to resolve the destination. The same product can appear on either side, so do not follow the examples into one fixed side. Use these flags exactly; do not guess another --type, --engine, or --page-size:

bash
dtscli job instances --region <region-id> --type RDS --engine MYSQL --usage-type <src|dest> --instance-id <instance-name> --page 1 --page-size 100

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/api-allowlist.md (reported line 31)May include surrounding context.

md
## Input and output boundary

Do not ask the user to paste raw CLI output. Accept only non-sensitive resource identifiers (`DtsJobId`, `DtsInstanceId`, `RequestId`) or redacted error information. Obtain values available through an allowlisted read-only query yourself.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 95)May include surrounding context.

md
## Input and output boundary

Do not ask the user to paste raw CLI output. Accept only non-sensitive resource identifiers (`DtsJobId`, `DtsInstanceId`, `RequestId`) or redacted error information. Obtain values available through an allowlisted read-only query yourself.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/credentials-and-security.md (reported line 16)May include surrounding context.

md
<a id="database-credential-security-boundary"></a>
## Database credential security boundary

Never ask the user to paste a database username, password, or database credential file through the conversation, command arguments, or tool results.

If the user provides any credential or secret in chat, do not use, repeat, validate, store, or pass it to any tool. Instruct the user to rotate or revoke the exposed value in its original system. Continue only with a replacement entered through the approved local flow. Never treat secrets pasted in chat as authorization for direct execution.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 129)May include surrounding context.

md
<a id="database-credential-security-boundary"></a>
## Database credential security boundary

Never ask the user to paste a database username, password, or database credential file through the conversation, command arguments, or tool results.

If the user provides any credential or secret in chat, do not use, repeat, validate, store, or pass it to any tool. Instruct the user to rotate or revoke the exposed value in its original system. Continue only with a replacement entered through the approved local flow. Never treat secrets pasted in chat as authorization for direct execution.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The file explicitly states that database usernames and passwords are stored locally as standard Base64 in files under the user's home directory. Base64 is reversible, not encryption, so compromise of the local account, backups, or filesystem access would directly expose live database credentials.

Content

Scanner excerpt · references/credentials-and-security.md (reported line 33)May include surrounding context.

md
`dtscli` stores one username/password set for each credential context under `.aliyun-dts/job-manager/credentials/` in the current user's home directory. A context identifies one database connection independently of whether it is used as the source or destination. It includes engine, instance type, region, and instance ID; PostgreSQL and MongoDB contexts also include the endpoint's `database`, while MySQL-family contexts do not. Reuse one credential set only when the complete contexts match. Consequently, PostgreSQL and MongoDB databases on the **same instance with different `database` values** (for example source `<source-database>` and destination `<destination-database>`) derive two independent credential contexts that must be initialized separately; `dtscli job create review` reports `role` and `stored` for each side in `credentials`. The CLI locates the corresponding credential set from `attempt_id`. `stored` means credentials exist locally; it does not prove connectivity.

MySQL-family credential files use `dts-{engine}-{instance_type}-{region}-{instance_id}.json`; PostgreSQL and MongoDB files use `dts-{engine}-{instance_type}-{region}-{instance_id}-{database}.json`. Underscores in an engine name are preserved, as in `polardb_pg`. Every label comes from the validated database connection context. If the complete name violates the portable safe-filename grammar or exceeds 240 characters, use `dts-{engine}-{instance_type}-{sha256-prefix}.json` instead, where `sha256-prefix` is the first 16 lowercase hexadecimal characters of the complete database connection context's SHA-256 digest. Never search for, rename, copy, or rewrite a credential file to preserve an old name. When a new plan cannot find its newly derived name, treat it as missing and enter it again through the browser workflow. The credential-set ID and its derivation are internal implementation details; never ask the user to supply or edit either, and never include an ID or its derivation in user-facing o
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/credentials-and-security.md (reported line 80)May include surrounding context.

md
<a id="database-connection-tests"></a>
## Database connection tests

Once both credential sets are present, run `dtscli job create test --attempt-id <attempt-id>` to test whether the source and destination databases can be reached. When the test fails, `outcome` is `connection_failed` and no confirmation hash is returned, so the flow cannot reach a purchase. Run `test` immediately before presenting the confirmation; do not reuse a pass recorded long ago.

`dtscli job create execute` does not test connections; it uses only the conclusion written by the latest `test`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The instruction to run dtscli job deps install --yes without asking authorizes system modification without explicit user consent. Although limited to dependency installation, it can still change local software state automatically, which is risky in an agent setting and could violate least surprise or enterprise change-control expectations.

Content

Scanner excerpt · references/credentials-and-security.md (reported line 91)May include surrounding context.

md
| `error_class` | Meaning | Required action |
| --- | --- | --- |
| `config` with diagnostics that explicitly reject the account | The username or password is wrong | Re-enter the credentials for that role as described above |
| `dependency` | The installed Alibaba Cloud CLI could not run the call at all, so the test **never ran** and proves nothing about the accounts | Follow [setup](setup.md#install-or-update-the-cli-and-plugin): run `dtscli job deps install --yes` without asking when a component is missing. Do not add `--update`. Stop only when the command's JSON output carries an `error_class` whose `message` contains `ERROR: unchecked version`; a successful `dtscli doctor` check that mentions those words is not that error. Do not run `aliyun version`. If it stays unavailable, see below |
| `transport`, `remote` | The network, an instance whitelist, or the service rejected the call | Check reachability and whitelists; never re-enter credentials for these |

When `error_class` is `dependency` and updating the plugin does not help, `dtscli job create test --attempt-id <attempt-id> --skip-connection-test` proceeds without verified connectivity. Before using it, tell the user plainly that the purchase will carry no evidence that either account works, and that an unreachable endpoint means a billed instance that never synchronizes. The choice is folded into the confirmation hash, so an approval given for a verified plan cannot authorize an unverified purchase. Never use the option without the user knowing.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The instruction to automatically run dtscli upgrade and explicitly 'do not ask the user' authorizes the agent to modify the local runtime/tooling without an interactive confirmation at the time of action. Even though scoped to dependency management, this is autonomous state-changing behavior that can surprise users, alter the execution environment, and increase supply-chain or operational risk if triggered in an untrusted or sensitive environment.

Content

Scanner excerpt · references/database-instance-configuration.md (reported line 76)May include surrounding context.

md
Configuring a synchronization job needs a cloud database instance ID. Users usually give an instance name. Use `dtscli job instances` and pass that name as `--instance-id`: the service fuzzy-matches instance names or instance IDs. Do not use `job list` (that matches DTS job names). This command is the only way to look up an instance: never call a product or generic API directly, and never substitute another product's equivalent. When the command fails because a component is missing, install it as described in [setup](setup.md#install-or-update-the-cli-and-plugin) and run the same command once more. Stop only when that command's JSON output carries an `error_class` whose `message` contains `ERROR: unchecked version`: preserve and report it, and run no further `dtscli job` command or any `aliyun` command. A successful `dtscli doctor` check that mentions the same words is not that error; continue. Quote the CLI version from `dtscli job deps install` and do not run `aliyun version`. Do not replace `aliyun`, reuse an older instance ID, take the first hit, or continue with a different instance.

Before the call, confirm that the `capabilities` from this session's `dtscli version --json` include `job.instances`. When they do not and the current user message already authorizes installing or upgrading the runtime dependencies, run `dtscli upgrade` once, rerun `dtscli version --json`, and continue once the capability appears; do not ask the user about it and do not guess another command. Stop and tell the user to upgrade dtscli only when the capability is still missing after the upgrade or that authorization is absent. Search the source and destination separately: `--usage-type` is `src` or `dest`. `--region` is that cloud database instance's region; if the region is unknown, ask the user first and do not retry other regions. Fill `--type`, `--engine`, and `--page-size` from the selected product. `ModName` is fixed to `SYNC` by the command; do not pass it. MongoDB listings ar
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/instance-classes-and-pricing.md (reported line 11)May include surrounding context.

md
## Class selection

Retain a supplied class when it remains supported and has a valid quotation; query only that class and do not ask the user to select it again. When no valid selection exists, obtain quotations for all reviewed classes, display only supported classes with complete quotations, RPS references, prices, and applicable warnings, and require the user to select one. Do not preselect or recommend a class from RPS or price alone.

When `instance_class` is omitted, the CLI compiles `small`. That is only a field default, not the user's choice: when the user has not selected a class, still display the quotations and require a selection under this section, then write the result into the public input.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 19)May include surrounding context.

md
## Class selection

Retain a supplied class when it remains supported and has a valid quotation; query only that class and do not ask the user to select it again. When no valid selection exists, obtain quotations for all reviewed classes, display only supported classes with complete quotations, RPS references, prices, and applicable warnings, and require the user to select one. Do not preselect or recommend a class from RPS or price alone.

When `instance_class` is omitted, the CLI compiles `small`. That is only a field default, not the user's choice: when the user has not selected a class, still display the quotations and require a selection under this section, then write the result into the public input.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 93)May include surrounding context.

md
## Class selection

Retain a supplied class when it remains supported and has a valid quotation; query only that class and do not ask the user to select it again. When no valid selection exists, obtain quotations for all reviewed classes, display only supported classes with complete quotations, RPS references, prices, and applicable warnings, and require the user to select one. Do not preselect or recommend a class from RPS or price alone.

When `instance_class` is omitted, the CLI compiles `small`. That is only a field default, not the user's choice: when the user has not selected a class, still display the quotations and require a selection under this section, then write the result into the public input.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly requires non-encrypted database connections for PostgreSQL and MongoDB sources/destinations, which would cause database credentials and replicated data to traverse the network without transport protection. In a workflow that collects credentials and performs connection tests for production databases, this materially increases exposure to interception, credential theft, and sensitive data disclosure, especially across cloud or cross-region links.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 121)May include surrounding context.

md
`init` saves the plan and attempt state. `review` only checks locally stored credentials and writes the plan summary; `test` runs the connection test. A storage failure stops the flow without an executable confirmation. Storage errors use `error_class="config"`; do not depend on the legacy `storage_failure_category` or classify local storage errors as cloud-service failures.

`init` generates an `attempt_id` shaped as `a<timestamp>-<16 hex digits>` and creates `.aliyun-dts/job-manager/creation-plans/<attempt-id>/` under the current user's home directory. Each attempt directory uses only the fixed names `plan.json`, `state.json`, and `execute.lock`; uniqueness comes from the parent `attempt_id`. Never put a job name, instance ID, or database name in the path. Never use a system temporary directory, a directory automatically removed when a child agent or task ends, or a repository path.

After missing credentials are corrected, rerun `review` using only the internal `attempt_id` returned by `init`, then run `test`; on `outcome=stored`, `job credentials collect` reports that `review` command as its `next_step`. After a recoverable pre-purchase connection failure is corrected, rerun only `test` with the same `attempt_id`. Both commands load and fully validate the retained `plan.json` and `state.json` from the fixed attempt directory. They never purchase, configure, or start a resource. Never resupply, reconstruct, copy, or edit the original public input. Stop on a plan-hash or state mismatch.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/job-creation.md (reported line 236)May include surrounding context.

md
| `outcome` | Handling |
| --- | --- |
| `credentials_required` | Collect credentials (follow `next_step`), then run `review` and `test` again |
| `connection_failed` | Act on `connection_error`; once corrected, resume `test` using only the same `attempt_id`. No confirmation hash is returned, so the flow cannot reach a purchase |
| `ready_for_confirmation` | Render the pre-execution review from `review`'s `summary` and this `connection_test`; when the user has approved the unchanged plan, follow `next_step` and run `execute --yes`. `confirmation_sha256` is an internal binding value and must never be displayed |

#### The `outcome` of execute

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The instruction to run dtscli job deps install --yes once without asking authorizes the agent to install software automatically on the host. Even though framed as dependency recovery, unattended package/plugin installation can modify the environment, introduce supply-chain risk, and violate least-privilege or change-control expectations.

Content

Scanner excerpt · references/job-creation.md (reported line 322)May include surrounding context.

md
| --- | --- |
| `usage` | The input, attempt ID, plan hash, or confirmation hash is invalid; correct it and start over, never skip it |
| `config` | The profile or the credentials are unusable; see [setup](setup.md) and [database credentials](credentials-and-security.md) |
| `dependency` | The Alibaba Cloud CLI or the DTS plugin is missing. Run `dtscli job deps install --yes` once without asking, then retry the same command once. Do not add `--update`. Stop only when the command's JSON output carries an `error_class` whose `message` contains `ERROR: unchecked version`; a successful `dtscli doctor` check that mentions those words is not that error. Do not replace `aliyun`, do not run `aliyun version`, and do not fetch the same data through another interface |
| `transport` | The network failed and the service provably did not act; retry once |
| `remote` | The service rejected the call; report the message and stop. A missing local plugin is not this case: when the message says the DTS plugin or Alibaba Cloud CLI is not installed, handle it as `dependency` |
| `indeterminate` | The write was sent but whether the service acted cannot be determined; never retry, check the console |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/job-lifecycle.md (reported line 42)May include surrounding context.

--region

text

When `redundant` is `true`, the operation would have no effect in the current state — for example the job is already in a terminal state — and no write is sent: explain why and stop.

The Alibaba Cloud CLI can be configured with a safety policy (`~/.aliyun/safety-policy.json`) that requires interactive confirmation for operations such as `dts:suspend*`. `dtscli` issues writes non-interactively and skips that prompt. Never work around this by running a CLI command with `--yes` outside `dtscli`.

Static analysis

No suspicious patterns detected.