Back to skill

Security audit

Alibabacloud Ecs Disaster Recovery Snapshot

Security checks for vulnerabilities and agentic risk

Overview

The skill supports a real Alibaba Cloud recovery workflow, but it also directs risky local installs, global plugin updates, and unsafe credential-handling examples.

Install only after reviewing the local setup steps. Prefer installing a verified Aliyun CLI yourself, avoid the remote setup.sh path, disable broad automatic plugin changes where possible, use a least-privilege RAM role or short-lived credentials, and do not paste or export long-lived access keys in agent-visible commands or logs. Expect this workflow to create cloud resources that may incur charges.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:53
Finding

Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:20
Finding

Unpinned Aliyun CLI Archives Are Installed Without Checksum or Signature Validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:61
Finding

Mandatory Automatic Plugin Installation and Unpinned Plugin Updates Expand Supply-Chain Exposure

Content
View full analysis
**Pre-check: Aliyun CLI plugin update required** > [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > [MUST] run `aliyun plugin update` to ensure that any existing plugins on your local machine are always up-to-date. ``` Related plugin installation guidance appears at `references/cli-installation-guide.md:499-506`: ```bash aliyun plugin install --names ecs vpc rds # List all available plugins aliyun plugin list-remote ``` ### Technical Analysis The Skill mandates two broad changes before executing its primary workflow: 1. It persistently enables automatic plugin installation. 2. It updates every existing plugin, rather than only the components required by the disaster-recovery operation. The instructions do not pin plugin versions, verify plugin signatures or hashes, constrain the plugin repository, or request separate confirmation for the update. Updating unrelated plugins violates minimization and expands the number of external components capable of affecting execution. The automatic-installation setting persists beyond the immediate operation. Future CLI commands may therefore retrieve and execute plugin components that were not present or reviewed when this Skill was audited. ### Attack Path 1. An attacker compromises a plugin publication account, repository, build pipeline, or plugin release. 2. The Skill enables automatic plugin installation and invokes the global update operation. 3. The compromised plugin is installed or updated without a pinned version or integrity verification. 4. The plugin executes as part of current or subsequent Aliyun CLI operations. 5. It captures credentials, alters API requests, falsifies output, or runs arbitrary code with the local user's privileges. ### ...[truncated 515 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/cli-installation-guide.md:103
Finding

Credential Guide Encourages Secrets in Command Arguments and Environment Variables

Content
View full analysis
\ --access-key-secret \ --region cn-hangzhou ``` The guide explicitly recommends this pattern: ```markdown All `aliyun configure` commands support non-interactive flags, which is the recommended approach — it works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts. ``` It also recommends exporting credentials: ```bash export ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id export ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret export ALIBABA_CLOUD_REGION_ID=cn-hangzhou ``` Temporary credentials are handled similarly: ```bash export ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id export ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret export ALIBABA_CLOUD_SECURITY_TOKEN=your_sts_token export ALIBABA_CLOUD_REGION_ID=cn-hangzhou ``` ### Technical Analysis Passing access keys and STS tokens as command-line arguments can expose them through: - Shell history. - CI/CD job logs. - Terminal recording and command auditing. - Process inspection on platforms that expose process argument lists. - Agent transcripts or command telemetry. Exported environment variables are inherited by child processes. This unnecessarily broadens the set of applications and plugins that can access the credentials and can lead to accidental disclosure in diagnostics, crash reports, container inspection, or CI environment dumps. The guide also creates a direct policy contradiction. `SKILL.md:68-74` prohibits asking for credentials, using literal credentials with `aliyun configu ...[truncated 1552 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (24)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs downloading and executing a remote shell script via curl and bash, which is a classic supply-chain and arbitrary code execution risk on the user's local machine. Even with user confirmation, embedding remote script execution inside a cloud recovery skill is dangerous because compromise of the download source, transport, or installer would lead to immediate local code execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed triggers include generic phrases such as "snapshot backup," "DR recovery," and the Chinese equivalent "灾备恢复," which are broad enough to match many unrelated backup or recovery tasks. Although the skill is specifically about Alibaba Cloud ECS cross-AZ snapshot workflows, the trigger list does not provide exclusions or constraints to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims the workflow is backup-only and that the original ECS instance remains untouched, but it also directs changes to the operator's local environment by installing/upgrading the Aliyun CLI and plugins. That mismatch is security-relevant because it expands the trust boundary from cloud backup actions into local machine modification, which can surprise users and increase exposure to supply-chain or endpoint risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mandating automatic plugin installation and blanket plugin updates broadens the skill's authority beyond the minimum needed for ECS snapshot recovery. This increases supply-chain exposure by allowing new or updated code to be fetched and executed locally without demonstrating necessity for the declared task.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
> **[MUST]** All CLI commands MUST follow these standards to avoid parameter errors.

| Rule                        | Correct                                                                                               | Incorrect                             |
| --------------------------- | ----------------------------------------------------------------------------------------------------- | ------------------------------------- |
| **Command name**      | `describe-instances` (kebab-case)                                                                   | `DescribeInstances` (PascalCase)    |
| **User agent**        | Always include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-disaster-recovery-snapshot/{session-id}` | Missing user-agent or session-id      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
| **Region parameter**  | Use `--biz-region-id` for commands that support it; use `--endpoint` only for `create-snapshot` and `attach-disk` | `--region-id` or `--RegionId`     |
| **Endpoint**          | Add `--endpoint ecs.<region>.aliyuncs.com` when CLI default region differs                          | Omitting endpoint                     |
| **List parameters**   | `--disk-id val1 val2` (space-separated)                                                             | `--disk-id.1 val1 --disk-id.2 val2` |
| **VSwitch parameter** | `--vswitch-id`                                                                                      | `--v-switch-id`                     |

**[MUST] CLI User-Agent** — Every `aliyun` CLI command that calls a cloud API must include:
`--user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-disaster-recovery-snapshot/{session-id}`

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 490)May include surrounding context.

md
full disk layout table.
## Reference Links

| Document                                                                                 | Description                                            |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| [CLI Installation Guide](references/cli-installation-guide.md)                              | Aliyun CLI installation and configuration instructions |
| [Error Handling Guide](references/error-handling.md)                                        | Retry strategies, timeout handling, error diagnosis    |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 175)May include surrounding context.

md
| Rule | Verification |
| --- | --- |
| No deletion without confirmation | Never calls delete-snapshot/delete-image/delete-instance without AskUserQuestion |
| No resource changes without user consent | VSwitch creation, spec changes always use AskUserQuestion |
| Source instance untouched | No stop/modify/delete operations on source |
| Credentials never exposed | No echo/print of AK/SK values |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 118)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill manifest says this skill is for ECS snapshot-based cross-AZ disaster recovery, but this file provides a general-purpose Aliyun CLI authentication guide covering six credential modes, including cross-account role assumption and elevated access patterns. That materially broadens the documented operational scope from a focused DR workflow to generic cloud administration capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples show direct use of access keys and explicitly note storage in ~/.aliyun/config.json, but the nearby workflow does not warn that these are sensitive long-lived credentials requiring local protection. In practice, this can lead users to paste secrets into commands, leave them in readable files, or reuse highly privileged keys in automation tied to the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guide includes cross-account and role-assumption modes such as RamRoleArn and RamRoleArnWithEcs that can facilitate elevated or lateral access beyond the disaster recovery use case. In an agent skill, documenting these modes without strong scoping or justification increases the chance that operators provision excessive privileges or use credentials with broader blast radius than necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The environment variable examples promote placing cloud credentials directly into shell environment variables without nearby cautions about exposure through shell history, process inspection, CI logs, and inherited subprocess environments. In an automation-oriented skill, this is risky because users may adopt the pattern in shared runners or multi-user systems where secrets can leak unintentionally.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 404)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes ECS snapshot recovery scenarios, but the guide's next steps instruct users to install multiple service plugins and explore commands including FC, which is unrelated to the stated ECS disaster recovery purpose. This expands the documented behavior beyond the skill's declared domain.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest frames the skill as snapshot-based disaster recovery and emphasizes that the original instance remains untouched, which suggests backup/recovery actions centered on snapshots, images, instances, and disks. This documentation explicitly includes creating new network infrastructure (ecs:CreateVSwitch) as part of the flow, which is a materially different side effect not surfaced in the skill's stated purpose and therefore creates an intent/documentation divergence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This reference file documents multiple state-changing Alibaba Cloud CLI commands that can create instances, snapshots, images, VSwitches, and disks, but it provides no adjacent warning that these operations may incur charges, alter infrastructure, or affect data handling. In an agent skill context, omission of such warnings increases the chance that users or downstream automation invoke destructive or costly actions without informed consent, especially because the commands are presented as ready-to-use operational steps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest-style description embeds Chinese trigger phrases in addition to English, but the file does not explain whether multilingual handling is optional, user-driven, or required for a region-specific deployment. Under the policy, language or locale behavior should be opt-in or clearly justified when a skill imposes specific language expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest repeatedly describes disaster recovery and restoring/launching resources in another AZ, distinguishing backup from migration. This heading labels the scenario as 'Full Instance Backup', which understates and misstates the actual documented outcome of creating an image, launching a new instance, and reattaching restored disks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest defines Scenario B as disk-level recovery: snapshot disks, create new disks from snapshots, and attach them to an existing target instance. Labeling the scenario as 'Disk-Level Backup' contradicts the described workflow because the documented permissions and steps go beyond backup into active restoration and attachment on another instance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.