T03 · Remote Payload Retrieval and Execution
- Location
references/script-templates.md:90- Finding
Unverified NodeSource installation script is executed as root
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent ECS deployment skill, but it grants and exercises high-impact cloud authority with unsafe install and credential-handling paths that need careful review.
Install only in a disposable or tightly scoped Alibaba Cloud account unless you first narrow the RAM permissions, use short-lived credentials, verify downloaded installers, and review .appmanager/config.yaml before deployment. Avoid deploying untrusted repositories, do not store real model API keys in project files, and be especially careful when targeting an existing ECS instance because the skill can stop processes, overwrite files, and run remote shell commands there.
references/script-templates.md:90Unverified NodeSource installation script is executed as root
scripts/deploy_toolkit.py:902Unvalidated configuration port enables root command injection through Cloud Assistant
references/init-and-credentials.md:52Mutable Alibaba Cloud CLI archives are installed without mandatory integrity verification
references/init-and-credentials.md:262Model-service API key is exposed through process arguments and plaintext project configuration
references/lessons-learned.md:49Downloaded GitHub release JAR is executed without integrity verification
references/ram-policies.md:10Recommended cloud policy grants account-wide destructive and command-execution permissions
The skill combines multiple high-risk behaviors flagged by the YARA rule: non-interactive execution, autonomous installs, destructive 'rm -rf' operations, defaulting to the current working directory, and remote deployment/persistence. In aggregate, this creates a powerful automation path that can modify the local machine, delete files, consume cloud resources, and leave long-running services active with limited user friction.
�署App、部署AI Agent、deploy to ECS、code deploy、deploy app、deploy agent、appmanager deploy、ECS code deploy、跑一下这个项目、把代码跑到ECS上、ECS上线。
---
# Deploy to Alibaba Cloud ECS via aliyun appmanager
## Overview
`aliyun appmanager` is an Agent-friendly CLI tool for one-click deployment of applications (App) and AI Agents to Alibaba Cloud ECS. It supports non-interactive mode (`--non-interactive`), structured JSON output (`--output json`), and streaming NDJSON responses.
**Default behavior**: When user invokes `/alibabacloud-ecs-code-deploy` without specifying a project path or URL, deploy the **current working directory** project to Alibaba Cloud ECS. If user provides a git URL, clone it to the current directory first, then `cd` into the cloned directory and proceed with deployment.
> **EXECUTION ORDER**: The Agent MUST follow the "Complete Deployment Workflow" section at the bottom of this document for the correct execution sequence. The Ta
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Referenced artifact was not completely inspected
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
>
> The toolkit's `check` output already includes an `→ AGENT: DO NOT stop. ASK user ...` line for each fixable issue — follow it verbatim (except for the "not installed" case, which is auto-handled).
>
> **MUST — Upgrade method priority**: brew-managed → `brew upgrade` (do NOT overwrite `/usr/local/bin/` again); sudo → overwrite `/usr/local/bin/`; no sudo → `~/bin/` + PATH persist (Unix). Scoop/Choco → `%USERPROFILE%\bin` + User PATH (Windows). Full priority rules → [references/init-and-credentials.md](references/init-and-credentials.md) § "CLI Install/Upgrade Method Priority". After install/upgrade, ALWAYS rerun `deploy_toolkit.py check` to confirm; if `which -a aliyun` still shows the old binary first, fix PATH order — DO NOT repeat the same overwrite.
## Observability (MANDATORY): User-Agent Injection
Referenced artifact was not completely inspected
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check
Referenced artifact was not completely inspected
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check
Referenced artifact was not completely inspected
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check
Referenced artifact was not completely inspected
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check
Referenced artifact was not completely inspected
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check
This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.
# (covers to /usr/local/bin, needs sudo), then run the install command
# printed by the script (see Task 1).
# - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
# `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
# appmanager run).
# ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
# by the aliyun CLI). After deletion, the next `aliyun appmanager` run
This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.
# (covers to /usr/local/bin, needs sudo), then run the install command
# printed by the script (see Task 1).
# - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
# `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
# appmanager run).
# ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
# by the aliyun CLI). After deletion, the next `aliyun appmanager` run
This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.
# (covers to /usr/local/bin, needs sudo), then run the install command
# printed by the script (see Task 1).
# - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
# `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
# appmanager run).
# ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
# by the aliyun CLI). After deletion, the next `aliyun appmanager` run
The workflow allows deleting '.appmanager' with 'rm -rf' to reinitialize deployment config. Even though the document asks for consent, the command is still destructive and can erase deployment state, scripts, and configuration, potentially causing data loss or accidental redeployments if the current directory is wrong.
# c. Inform the user "About to delete the existing deployment config under ./.appmanager/. This is irreversible." and obtain consent
# Recommended safer alternative: back up first
# mv .appmanager .appmanager.bak.$(date +%Y%m%d%H%M%S)
# Only after explicit user consent: rm -rf ./.appmanager
# → Run: aliyun appmanager init --non-interactive --name <DIR_NAME> --type <app|agent> --region <REGION> [--port <PORT>] [--ecs existing --instance-id <ID>] [--model qwen3.6-plus --api-key "$API_KEY"]
# (See references/init-and-credentials.md for full flag combinations by type)
# → Then generate start/stop scripts and write to config.yaml:
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
| Flag | Description |
|------|-------------|
| `--config PATH` | Custom config file (default: `.appmanager/config.yaml`) |
| `--overwrite` | Force overwrite existing files in OSS |
| `--dry-run` | Validate only, do not execute deployment |
| `--output json` | Output NDJSON stream (Agent-friendly) |
| `--name TEXT` | Override app name |
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
**Version requirements**: aliyun CLI >= 3.3.19, appmanager-cli >= 1.1.1
> **🪟 Windows users**: The `curl | sudo tar xz`, `brew`, `~/.zshrc`/`~/.bashrc` PATH and `~/.aliyun/appmanager-venv/bin/python` snippets in this section are **Unix-only (Linux/macOS)**. On native Windows (cmd/PowerShell), skip them and jump to the **"Windows (PowerShell) install"** subsection below. `deploy_toolkit.py check` auto-detects the platform (`os.name == "nt"`) and already prints the correct Windows PowerShell guidance — the manual steps here are only for when the toolkit script is unavailable.
> **⚠️ Privilege requirement (Unix)**: The install commands below extract to `/usr/local/bin/`, which requires elevated privileges (`sudo` on Linux/macOS for non-root users). If running as a non-root user, prepend `sudo` to the `tar` step. Alternatively, extract to a user-writable directory in `$PATH` (e.g., `~/.local/bin`). On Windows there is no `sudo`; install into `%USERPROFILE%\bin` (no admin rights needed) — see the Windows subsection.
> **⚠️ Supply chain note**: The downloads come from Alibaba Cloud's official OSS bucket over HTTPS. For higher assurance, verify the binary's SHA256 checksum against the version listed at https://help.aliyun.com/document_detail/121541.html before adding to `$PATH`.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
**Version requirements**: aliyun CLI >= 3.3.19, appmanager-cli >= 1.1.1
> **🪟 Windows users**: The `curl | sudo tar xz`, `brew`, `~/.zshrc`/`~/.bashrc` PATH and `~/.aliyun/appmanager-venv/bin/python` snippets in this section are **Unix-only (Linux/macOS)**. On native Windows (cmd/PowerShell), skip them and jump to the **"Windows (PowerShell) install"** subsection below. `deploy_toolkit.py check` auto-detects the platform (`os.name == "nt"`) and already prints the correct Windows PowerShell guidance — the manual steps here are only for when the toolkit script is unavailable.
> **⚠️ Privilege requirement (Unix)**: The install commands below extract to `/usr/local/bin/`, which requires elevated privileges (`sudo` on Linux/macOS for non-root users). If running as a non-root user, prepend `sudo` to the `tar` step. Alternatively, extract to a user-writable directory in `$PATH` (e.g., `~/.local/bin`). On Windows there is no `sudo`; install into `%USERPROFILE%\bin` (no admin rights needed) — see the Windows subsection.
> **⚠️ Supply chain note**: The downloads come from Alibaba Cloud's official OSS bucket over HTTPS. For higher assurance, verify the binary's SHA256 checksum against the version listed at https://help.aliyun.com/document_detail/121541.html before adding to `$PATH`.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 2. Check appmanager-cli version (only if ~/.aliyun/appmanager-venv exists)
~/.aliyun/appmanager-venv/bin/python -c "from importlib.metadata import version; print(version('appmanager-cli'))" 2>/dev/null
# → < 1.1.1 or fails: rm -rf ~/.aliyun/appmanager-venv (auto-recreates on next run)
# 3. Install aliyun CLI — choose ONE path below by priority
# Priority A: macOS already manages aliyun-cli via Homebrew -> upgrade with brew
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 2. Check appmanager-cli version (only if ~/.aliyun/appmanager-venv exists)
~/.aliyun/appmanager-venv/bin/python -c "from importlib.metadata import version; print(version('appmanager-cli'))" 2>/dev/null
# → < 1.1.1 or fails: rm -rf ~/.aliyun/appmanager-venv (auto-recreates on next run)
# 3. Install aliyun CLI — choose ONE path below by priority
# Priority A: macOS already manages aliyun-cli via Homebrew -> upgrade with brew
Piping a network download directly into a privileged tar extraction combines remote content retrieval and root-level execution without an inspection boundary. If the download source, TLS trust, DNS, or hosting bucket were compromised, a malicious archive could write arbitrary files into privileged locations and fully compromise the host.
# Priority B: system-directory install (recommended; writing to /usr/local/bin needs sudo)
# macOS Apple Silicon:
curl --connect-timeout 30 --max-time 120 -fsSL https://aliyun-cli.oss-cn-hangzhou.aliyuncs.com/aliyun-cli-macosx-latest-arm64.tgz | sudo tar xz -C /usr/local/bin/
# macOS Intel:
curl --connect-timeout 30 --max-time 120 -fsSL https://aliyun-cli.oss-cn-hangzhou.aliyuncs.com/aliyun-cli-macosx-latest-amd64.tgz | sudo tar xz -C /usr/local/bin/
# Linux amd64:
No suspicious patterns detected.