Back to skill

Security audit

alibabacloud-ecs-code-deploy

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent ECS deployment skill, but it grants and exercises high-impact cloud authority with unsafe install and credential-handling paths that need careful review.

Install only in a disposable or tightly scoped Alibaba Cloud account unless you first narrow the RAM permissions, use short-lived credentials, verify downloaded installers, and review .appmanager/config.yaml before deployment. Avoid deploying untrusted repositories, do not store real model API keys in project files, and be especially careful when targeting an existing ECS instance because the skill can stop processes, overwrite files, and run remote shell commands there.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/script-templates.md:90
Finding

Unverified NodeSource installation script is executed as root

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/deploy_toolkit.py:902
Finding

Unvalidated configuration port enables root command injection through Cloud Assistant

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/init-and-credentials.md:52
Finding

Mutable Alibaba Cloud CLI archives are installed without mandatory integrity verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/init-and-credentials.md:262
Finding

Model-service API key is exposed through process arguments and plaintext project configuration

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/lessons-learned.md:49
Finding

Downloaded GitHub release JAR is executed without integrity verification

Content
View full analysis
/root/app.log mkdir -p /root && cd /root if [ ! -f .jar ]; then curl -fSL "https://github.com///releases/download/v/-.jar" -o /root/.jar fi pkill -f '.jar' || true nohup java -Xmx384m -jar /root/.jar --server.port=8090 >> /root/app.log 2>&1 & ``` ### Technical Analysis The troubleshooting guidance recommends downloading a prebuilt executable JAR from a GitHub release and immediately launching it. It does not require a checksum, signed provenance statement, publisher signature, or validation that the repository and release asset are the intended official source. Pinning a release version reduces accidental change but does not protect against compromise of the repository owner, release workflow, GitHub account, or asset replacement. The JAR runs in the documented root deployment context and therefore receives broad local privileges. Using a prebuilt release artifact can be operationally appropriate for resource-constrained ECS instances, but executing it without cryptographic provenance verification is not necessary for the deployment function. ### Attack Path 1. An attacker compromises the selected repository, maintainer account, release workflow, or release asset. 2. The release JAR is replaced or a malicious release is presented as legitimate. 3. The Agent applies the documented troubleshooting pattern. 4. The ECS instance downloads the attacker-controlled JAR to `/root`. 5. Java launches the JAR under the deployment account. 6. Malicious initialization code gains control of the ECS host and application environment. ### Impact Assessment Successful exploitation provides arbitrary code execution under the deploy ...[truncated 208 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/ram-policies.md:10
Finding

Recommended cloud policy grants account-wide destructive and command-execution permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (86)

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
98% confidence
Finding

The skill combines multiple high-risk behaviors flagged by the YARA rule: non-interactive execution, autonomous installs, destructive 'rm -rf' operations, defaulting to the current working directory, and remote deployment/persistence. In aggregate, this creates a powerful automation path that can modify the local machine, delete files, consume cloud resources, and leave long-running services active with limited user friction.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
�署App、部署AI Agent、deploy to ECS、code deploy、deploy app、deploy agent、appmanager deploy、ECS code deploy、跑一下这个项目、把代码跑到ECS上、ECS上线。
---

# Deploy to Alibaba Cloud ECS via aliyun appmanager

## Overview

`aliyun appmanager` is an Agent-friendly CLI tool for one-click deployment of applications (App) and AI Agents to Alibaba Cloud ECS. It supports non-interactive mode (`--non-interactive`), structured JSON output (`--output json`), and streaming NDJSON responses.

**Default behavior**: When user invokes `/alibabacloud-ecs-code-deploy` without specifying a project path or URL, deploy the **current working directory** project to Alibaba Cloud ECS. If user provides a git URL, clone it to the current directory first, then `cd` into the cloned directory and proceed with deployment.

> **EXECUTION ORDER**: The Agent MUST follow the "Complete Deployment Workflow" section at the bottom of this document for the correct execution sequence. The Ta

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

md
redentials in one run. Only if the script file is missing, use the fallback in [references/init-and-credentials.md](references/init-and-credentials.md).

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
>
> The toolkit's `check` output already includes an `→ AGENT: DO NOT stop. ASK user ...` line for each fixable issue — follow it verbatim (except for the "not installed" case, which is auto-handled).
>
> **MUST — Upgrade method priority**: brew-managed → `brew upgrade` (do NOT overwrite `/usr/local/bin/` again); sudo → overwrite `/usr/local/bin/`; no sudo → `~/bin/` + PATH persist (Unix). Scoop/Choco → `%USERPROFILE%\bin` + User PATH (Windows). Full priority rules → [references/init-and-credentials.md](references/init-and-credentials.md) § "CLI Install/Upgrade Method Priority". After install/upgrade, ALWAYS rerun `deploy_toolkit.py check` to confirm; if `which -a aliyun` still shows the old binary first, fix PATH order — DO NOT repeat the same overwrite.

## Observability (MANDATORY): User-Agent Injection

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 362)May include surrounding context.

md
- **README only has Docker** → Check image accessibility (see [references/script-templates.md](references/script-templates.md) "Docker Image Accessibility Check

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
#         (covers to /usr/local/bin, needs sudo), then run the install command
#         printed by the script (see Task 1).
#       - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
#         `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
#         appmanager run).
#         ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
#            by the aliyun CLI). After deletion, the next `aliyun appmanager` run

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
#         (covers to /usr/local/bin, needs sudo), then run the install command
#         printed by the script (see Task 1).
#       - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
#         `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
#         appmanager run).
#         ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
#            by the aliyun CLI). After deletion, the next `aliyun appmanager` run

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate points to the same recursive deletion of the appmanager virtual environment. In a skill that already performs shell execution and environment manipulation, destructive deletion compounds operational risk and can be abused or accidentally misapplied.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
#         (covers to /usr/local/bin, needs sudo), then run the install command
#         printed by the script (see Task 1).
#       - appmanager-cli < 1.1.1 or BROKEN venv: ASK user to approve
#         `rm -rf ~/.aliyun/appmanager-venv` (auto-recreates on next aliyun
#         appmanager run).
#         ⚠️ This path is fixed at ~/.aliyun/appmanager-venv (the venv is self-managed
#            by the aliyun CLI). After deletion, the next `aliyun appmanager` run

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The workflow allows deleting '.appmanager' with 'rm -rf' to reinitialize deployment config. Even though the document asks for consent, the command is still destructive and can erase deployment state, scripts, and configuration, potentially causing data loss or accidental redeployments if the current directory is wrong.

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

md
#        c. Inform the user "About to delete the existing deployment config under ./.appmanager/. This is irreversible." and obtain consent
#      Recommended safer alternative: back up first
#        mv .appmanager .appmanager.bak.$(date +%Y%m%d%H%M%S)
#      Only after explicit user consent: rm -rf ./.appmanager
# → Run: aliyun appmanager init --non-interactive --name <DIR_NAME> --type <app|agent> --region <REGION> [--port <PORT>] [--ecs existing --instance-id <ID>] [--model qwen3.6-plus --api-key "$API_KEY"]
#   (See references/init-and-credentials.md for full flag combinations by type)
# → Then generate start/stop scripts and write to config.yaml:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/deploy-output-and-management.md (reported line 8)May include surrounding context.

md
| Flag | Description |
|------|-------------|
| `--config PATH` | Custom config file (default: `.appmanager/config.yaml`) |
| `--overwrite` | Force overwrite existing files in OSS |
| `--dry-run` | Validate only, do not execute deployment |
| `--output json` | Output NDJSON stream (Agent-friendly) |
| `--name TEXT` | Override app name |

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/init-and-credentials.md (reported line 51)May include surrounding context.

md
**Version requirements**: aliyun CLI >= 3.3.19, appmanager-cli >= 1.1.1

> **🪟 Windows users**: The `curl | sudo tar xz`, `brew`, `~/.zshrc`/`~/.bashrc` PATH and `~/.aliyun/appmanager-venv/bin/python` snippets in this section are **Unix-only (Linux/macOS)**. On native Windows (cmd/PowerShell), skip them and jump to the **"Windows (PowerShell) install"** subsection below. `deploy_toolkit.py check` auto-detects the platform (`os.name == "nt"`) and already prints the correct Windows PowerShell guidance — the manual steps here are only for when the toolkit script is unavailable.

> **⚠️ Privilege requirement (Unix)**: The install commands below extract to `/usr/local/bin/`, which requires elevated privileges (`sudo` on Linux/macOS for non-root users). If running as a non-root user, prepend `sudo` to the `tar` step. Alternatively, extract to a user-writable directory in `$PATH` (e.g., `~/.local/bin`). On Windows there is no `sudo`; install into `%USERPROFILE%\bin` (no admin rights needed) — see the Windows subsection.
> **⚠️ Supply chain note**: The downloads come from Alibaba Cloud's official OSS bucket over HTTPS. For higher assurance, verify the binary's SHA256 checksum against the version listed at https://help.aliyun.com/document_detail/121541.html before adding to `$PATH`.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/init-and-credentials.md (reported line 107)May include surrounding context.

md
**Version requirements**: aliyun CLI >= 3.3.19, appmanager-cli >= 1.1.1

> **🪟 Windows users**: The `curl | sudo tar xz`, `brew`, `~/.zshrc`/`~/.bashrc` PATH and `~/.aliyun/appmanager-venv/bin/python` snippets in this section are **Unix-only (Linux/macOS)**. On native Windows (cmd/PowerShell), skip them and jump to the **"Windows (PowerShell) install"** subsection below. `deploy_toolkit.py check` auto-detects the platform (`os.name == "nt"`) and already prints the correct Windows PowerShell guidance — the manual steps here are only for when the toolkit script is unavailable.

> **⚠️ Privilege requirement (Unix)**: The install commands below extract to `/usr/local/bin/`, which requires elevated privileges (`sudo` on Linux/macOS for non-root users). If running as a non-root user, prepend `sudo` to the `tar` step. Alternatively, extract to a user-writable directory in `$PATH` (e.g., `~/.local/bin`). On Windows there is no `sudo`; install into `%USERPROFILE%\bin` (no admin rights needed) — see the Windows subsection.
> **⚠️ Supply chain note**: The downloads come from Alibaba Cloud's official OSS bucket over HTTPS. For higher assurance, verify the binary's SHA256 checksum against the version listed at https://help.aliyun.com/document_detail/121541.html before adding to `$PATH`.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/init-and-credentials.md (reported line 69)May include surrounding context.

md
# 2. Check appmanager-cli version (only if ~/.aliyun/appmanager-venv exists)
~/.aliyun/appmanager-venv/bin/python -c "from importlib.metadata import version; print(version('appmanager-cli'))" 2>/dev/null
# → < 1.1.1 or fails: rm -rf ~/.aliyun/appmanager-venv (auto-recreates on next run)

# 3. Install aliyun CLI — choose ONE path below by priority
#    Priority A: macOS already manages aliyun-cli via Homebrew -> upgrade with brew

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/init-and-credentials.md (reported line 69)May include surrounding context.

md
# 2. Check appmanager-cli version (only if ~/.aliyun/appmanager-venv exists)
~/.aliyun/appmanager-venv/bin/python -c "from importlib.metadata import version; print(version('appmanager-cli'))" 2>/dev/null
# → < 1.1.1 or fails: rm -rf ~/.aliyun/appmanager-venv (auto-recreates on next run)

# 3. Install aliyun CLI — choose ONE path below by priority
#    Priority A: macOS already manages aliyun-cli via Homebrew -> upgrade with brew

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Piping a network download directly into a privileged tar extraction combines remote content retrieval and root-level execution without an inspection boundary. If the download source, TLS trust, DNS, or hosting bucket were compromised, a malicious archive could write arbitrary files into privileged locations and fully compromise the host.

Content

Scanner excerpt · references/init-and-credentials.md (reported line 78)May include surrounding context.

md
#    Priority B: system-directory install (recommended; writing to /usr/local/bin needs sudo)
#    macOS Apple Silicon:
curl --connect-timeout 30 --max-time 120 -fsSL https://aliyun-cli.oss-cn-hangzhou.aliyuncs.com/aliyun-cli-macosx-latest-arm64.tgz | sudo tar xz -C /usr/local/bin/
#    macOS Intel:
curl --connect-timeout 30 --max-time 120 -fsSL https://aliyun-cli.oss-cn-hangzhou.aliyuncs.com/aliyun-cli-macosx-latest-amd64.tgz | sudo tar xz -C /usr/local/bin/
#    Linux amd64:

Static analysis

No suspicious patterns detected.