T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:53- Finding
Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill supports a real Alibaba Cloud recovery workflow, but it also directs risky local installs, global plugin updates, and unsafe credential-handling examples.
Install only after reviewing the local setup steps. Prefer installing a verified Aliyun CLI yourself, avoid the remote setup.sh path, disable broad automatic plugin changes where possible, use a least-privilege RAM role or short-lived credentials, and do not paste or export long-lived access keys in agent-visible commands or logs. Expect this workflow to create cloud resources that may incur charges.
SKILL.md:53Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification
references/cli-installation-guide.md:20Unpinned Aliyun CLI Archives Are Installed Without Checksum or Signature Validation
SKILL.md:61Mandatory Automatic Plugin Installation and Unpinned Plugin Updates Expand Supply-Chain Exposure
references/cli-installation-guide.md:103Credential Guide Encourages Secrets in Command Arguments and Environment Variables
The skill instructs downloading and executing a remote shell script via curl and bash, which is a classic supply-chain and arbitrary code execution risk on the user's local machine. Even with user confirmation, embedding remote script execution inside a cloud recovery skill is dangerous because compromise of the download source, transport, or installer would lead to immediate local code execution.
The listed triggers include generic phrases such as "snapshot backup," "DR recovery," and the Chinese equivalent "灾备恢复," which are broad enough to match many unrelated backup or recovery tasks. Although the skill is specifically about Alibaba Cloud ECS cross-AZ snapshot workflows, the trigger list does not provide exclusions or constraints to prevent unintended invocation.
The skill claims the workflow is backup-only and that the original ECS instance remains untouched, but it also directs changes to the operator's local environment by installing/upgrading the Aliyun CLI and plugins. That mismatch is security-relevant because it expands the trust boundary from cloud backup actions into local machine modification, which can surprise users and increase exposure to supply-chain or endpoint risk.
Mandating automatic plugin installation and blanket plugin updates broadens the skill's authority beyond the minimum needed for ECS snapshot recovery. This increases supply-chain exposure by allowing new or updated code to be fetched and executed locally without demonstrating necessity for the declared task.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
> **[MUST]** All CLI commands MUST follow these standards to avoid parameter errors.
| Rule | Correct | Incorrect |
| --------------------------- | ----------------------------------------------------------------------------------------------------- | ------------------------------------- |
| **Command name** | `describe-instances` (kebab-case) | `DescribeInstances` (PascalCase) |
| **User agent** | Always include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-disaster-recovery-snapshot/{session-id}` | Missing user-agent or session-id |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| **Region parameter** | Use `--biz-region-id` for commands that support it; use `--endpoint` only for `create-snapshot` and `attach-disk` | `--region-id` or `--RegionId` |
| **Endpoint** | Add `--endpoint ecs.<region>.aliyuncs.com` when CLI default region differs | Omitting endpoint |
| **List parameters** | `--disk-id val1 val2` (space-separated) | `--disk-id.1 val1 --disk-id.2 val2` |
| **VSwitch parameter** | `--vswitch-id` | `--v-switch-id` |
**[MUST] CLI User-Agent** — Every `aliyun` CLI command that calls a cloud API must include:
`--user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-disaster-recovery-snapshot/{session-id}`
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
full disk layout table.
## Reference Links
| Document | Description |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| [CLI Installation Guide](references/cli-installation-guide.md) | Aliyun CLI installation and configuration instructions |
| [Error Handling Guide](references/error-handling.md) | Retry strategies, timeout handling, error diagnosis |
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Rule | Verification |
| --- | --- |
| No deletion without confirmation | Never calls delete-snapshot/delete-image/delete-instance without AskUserQuestion |
| No resource changes without user consent | VSwitch creation, spec changes always use AskUserQuestion |
| Source instance untouched | No stop/modify/delete operations on source |
| Credentials never exposed | No echo/print of AK/SK values |
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/
### Windows
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once
### Configuration Modes
The skill manifest says this skill is for ECS snapshot-based cross-AZ disaster recovery, but this file provides a general-purpose Aliyun CLI authentication guide covering six credential modes, including cross-account role assumption and elevated access patterns. That materially broadens the documented operational scope from a focused DR workflow to generic cloud administration capability.
The examples show direct use of access keys and explicitly note storage in ~/.aliyun/config.json, but the nearby workflow does not warn that these are sensitive long-lived credentials requiring local protection. In practice, this can lead users to paste secrets into commands, leave them in readable files, or reuse highly privileged keys in automation tied to the skill.
The guide includes cross-account and role-assumption modes such as RamRoleArn and RamRoleArnWithEcs that can facilitate elevated or lateral access beyond the disaster recovery use case. In an agent skill, documenting these modes without strong scoping or justification increases the chance that operators provision excessive privileges or use credentials with broader blast radius than necessary.
The environment variable examples promote placing cloud credentials directly into shell environment variables without nearby cautions about exposure through shell history, process inspection, CI logs, and inherited subprocess environments. In an automation-oriented skill, this is risky because users may adopt the pattern in shared runners or multi-user systems where secrets can leak unintentionally.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Restrict permissions
chmod 600 ~/.aliyun/config.json
The manifest describes ECS snapshot recovery scenarios, but the guide's next steps instruct users to install multiple service plugins and explore commands including FC, which is unrelated to the stated ECS disaster recovery purpose. This expands the documented behavior beyond the skill's declared domain.
The manifest frames the skill as snapshot-based disaster recovery and emphasizes that the original instance remains untouched, which suggests backup/recovery actions centered on snapshots, images, instances, and disks. This documentation explicitly includes creating new network infrastructure (ecs:CreateVSwitch) as part of the flow, which is a materially different side effect not surfaced in the skill's stated purpose and therefore creates an intent/documentation divergence.
This reference file documents multiple state-changing Alibaba Cloud CLI commands that can create instances, snapshots, images, VSwitches, and disks, but it provides no adjacent warning that these operations may incur charges, alter infrastructure, or affect data handling. In an agent skill context, omission of such warnings increases the chance that users or downstream automation invoke destructive or costly actions without informed consent, especially because the commands are presented as ready-to-use operational steps.
The manifest-style description embeds Chinese trigger phrases in addition to English, but the file does not explain whether multilingual handling is optional, user-driven, or required for a region-specific deployment. Under the policy, language or locale behavior should be opt-in or clearly justified when a skill imposes specific language expectations.
The manifest repeatedly describes disaster recovery and restoring/launching resources in another AZ, distinguishing backup from migration. This heading labels the scenario as 'Full Instance Backup', which understates and misstates the actual documented outcome of creating an image, launching a new instance, and reattaching restored disks.
The manifest defines Scenario B as disk-level recovery: snapshot disks, create new disks from snapshots, and attach them to an existing target instance. Labeling the scenario as 'Disk-Level Backup' contradicts the described workflow because the documented permissions and steps go beyond backup into active restoration and attachment on another instance.
No suspicious patterns detected.