Security checks for vulnerabilities and agentic risk
Overview
This skill has a legitimate GPU-diagnosis purpose, but it gives agents high-impact cloud command authority with weak input validation and mutable installation/plugin update steps.
Review before installing. Use only with a tightly scoped Alibaba Cloud RAM identity and explicit instance lists, avoid tag values or region inputs from untrusted users, verify CLI and plugin sources independently, and treat scheduled mode as persistent cloud automation that must be tracked and cleaned up manually.
REGION_ID originates from user input and is interpolated into a shell command without quoting or prior syntactic validation. The command is itself intended to validate the region, meaning the untrusted value reaches the shell before validation occurs.
If the agent executes the rendered command through a shell, metacharacters such as semicolons, command substitutions, pipes, or redirections can change the command structure. For example, a value containing cn-test; attacker-command would cause the shell to execute an additional command rather than treating the entire value as a region argument.
Attack Path
An attacker provides a crafted region value containing shell syntax.
The agent substitutes the value directly into ${REGION_ID}.
The rendered validation command is passed to a shell.
The shell parses the injected metacharacters as additional syntax.
The attacker-controlled command executes with the privileges and environment of the agent process.
Impact Assessment
Successful exploitation permits arbitrary local command execution under the account running the agent. Depending on that account's privileges, this may expose local files, Alibaba Cloud CLI configuration and credentials, network-accessible resources, or other tools available to the process. If the agent runs with elevated privileges, the impact expands accordingly.
Remediation
View remediation
Remediation Suggestions
Validate REGION_ID before command construction using a strict allowlist derived from trusted region metadata or a conservative syntax rule.
Do not construct commands as shell strings. Invoke the Alibaba Cloud CLI using an argument array so the region remains one argument.
If a shell is unavoidable, apply robust shell escaping and quote the value:
bash
--region "${REGION_ID}"
Quoting alone should be treated as defense in depth, not a substitute for validation.
Reject control characters, whitespace, command substitutions, shell operators, and unexpected punctuation.
Add tests with values containing ;, |, $(), backticks, quotes, newlines, and redirections.
T09 · Insecure Skill Coding Practices
Error
Location
SKILL.md:259
Finding
Shell Command Injection Through Unvalidated Tag Key and Value
Content
View full analysis
Vulnerability Details
File Location: SKILL.md, lines 259-266 Vulnerability Type: OS command injection through unsafe quoted interpolation Risk Level: High
bash
- Tag filtering: query matching instances first:
```bash
aliyun ecs describe-instances \
--user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-gpu-diagnosis/{session-id} \
--biz-region-id '${REGION_ID}' \
--region '${REGION_ID}' \
--tag Key='${TAG_KEY}' Value='${TAG_VALUE}' # omit Value= to match all values of the Key
```
Technical Analysis
TAG_KEY and TAG_VALUE are user-controlled values embedded inside single-quoted shell text. No validation or escaping procedure is specified for either field.
Static single quotes do not safely quote an interpolated value when that value can itself contain a single quote. A malicious value can close the intended quote, introduce shell operators or command substitutions, and then restore syntactic validity. The same general risk also applies to other dynamically interpolated fields if the agent renders the template as a shell command.
Attack Path
An attacker requests scheduled diagnosis using a crafted tag key or value.
The supplied value contains a single quote followed by shell syntax.
The agent substitutes that value into Key='${TAG_KEY}' or Value='${TAG_VALUE}'.
The injected quote terminates the intended shell argument.
The shell interprets the remaining attacker-controlled text as commands.
Those commands execute while the agent is resolving target ECS instances.
Impact Assessment
Exploitation allows arbitrary command execution on the system running the skill, with the privileges of the agent process. The attacker may access local data, CLI profiles, environment variables, or cloud credentials available to that process and may use those credentials within their granted RAM permissions.
Remediation
View remediation
Remediation Suggestions
Pass the tag key and value as separate process arguments without invoking a shell.
Enforce Alibaba Cloud's documented tag constraints before execution, including maximum lengths and permitted character sets.
Explicitly reject quotes, control characters, newlines, shell operators, backticks, and command-substitution syntax.
Use a structured SDK request rather than shell-rendered CLI commands where practical.
Apply equivalent validation to REGION_ID, instance IDs, command names, Cron expressions, and all other values rendered into commands.
Add adversarial tests covering quote termination and multiline input.
T08 · Insecure Dependencies
Warning
Location
SKILL.md:44
Finding
Mandatory Execution of Mutable Automatically Installed Plugins
Content
View full analysis
Vulnerability Details
File Location: SKILL.md, lines 44-45 and 173-185 Vulnerability Type: Unpinned and automatically updated executable dependencies Risk Level: Medium
bash
- MUST run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation.
- MUST run `aliyun plugin update` to ensure local plugins are up-to-date.
The fixed Base64 content is documented as decoding to:
bash
if acs-plugin-manager --list --local | grep ACS-ECS-GpuCheck > /dev/null 2>&1; then acs-plugin-manager --remove --plugin ACS-ECS-GpuCheck; fi; acs-plugin-manager --exec --plugin ACS-ECS-GpuCheck
Technical Analysis
The skill requires automatic Alibaba Cloud CLI plugin installation and unconditional plugin updates without specifying a reviewed version, cryptographic digest, or signature-verification procedure. It also removes the locally installed ACS-ECS-GpuCheck component before executing that plugin on target ECS instances.
Consequently, the executable implementation used during a diagnosis can differ from the implementation present when the skill was audited. An upstream compromise, unexpected release, account takeover, or distribution-channel issue could introduce code that is automatically accepted and executed.
The Base64 literal itself is not a hidden payload: it decodes to the plugin-manager co
...[truncated 1099 chars]
Remediation
View remediation
Remediation Suggestions
Pin reviewed CLI and diagnostic-plugin versions instead of using mutable latest versions.
Verify vendor signatures or published cryptographic hashes before executing downloaded components.
Remove the unconditional aliyun plugin update requirement and disable automatic installation by default.
Do not remove a verified local plugin before every run.
Require explicit user approval before installing, updating, removing, or replacing executable dependencies.
Record the resolved plugin version and digest in diagnosis logs for auditability.
Restrict Cloud Assistant and RAM permissions to only the required instances and actions.
Test plugin updates in a controlled environment before production deployment.
T08 · Insecure Dependencies
Warning
Location
references/cli-installation.md:29
Finding
Unverified Privileged Installation of Mutable CLI Binaries
Content
View full analysis
Vulnerability Details
File Location: references/cli-installation.md, lines 29-36 and 71-88 Vulnerability Type: Unverified binary download and privileged installation Risk Level: Medium
# Linux x86_64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
tar -xzf aliyun-cli-linux-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/
# Linux ARM64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz
tar -xzf aliyun-cli-linux-latest-arm64.tgz && sudo mv aliyun /usr/local/bin/
# Windows PowerShell
Invoke-WebRequest -Uri "https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip" -OutFile "aliyun-cli.zip"
Expand-Archive -Path aliyun-cli.zip -DestinationPath C:\aliyun-cli -Force
Technical Analysis
The installation guide downloads mutable latest archives, extracts them, and installs or overwrites executable files without checksum or digital-signature verification. On Unix-like systems, the executable is moved into /usr/local/bin using sudo, placing it in a commonly trusted system-wide command path.
HTTPS provides transport protection but does not pin the artifact to a reviewed release. It does not protect against compromise of the publisher, build process, storage account, or signing infrastructure, nor does it ensure that a future latest archive matches the version reviewed during this audit.
Attack Path
The upstream archive, distribution account, or release pipeline is compromised, or the mutable archive is replaced with an unsafe build.
A user follows the s
...[truncated 798 chars]
Remediation
View remediation
Remediation Suggestions
Replace latest URLs with explicit, reviewed version URLs.
Publish an expected SHA-256 or stronger digest and verify it before extraction:
bash
YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]
High
Category
YARA Match
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
Content
Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.
md
---
name: alibabacloud-ecs-gpu-diagnosis
description: >
Diagnose GPU issues on Alibaba Cloud ECS GPU instances: GPU device status, driver issues, and GPU hardware failures.
Use when users ask to check the GPU status of their GPU instances, detect whether the GPU device is visible, verify that the GPU driver is installed correctly, or troubleshoot GPU anomalies such as GPU not visible or deep learning task failures.
Run Console Diagnosis or Cloud Assistant Diagnosis (RunCommand) to detect GPU hardware failures, perform batch diagnosis of GPU servers, or create scheduled (periodic) diagnosis tasks via CreateCommand and InvokeComm
Direct Prompt Extraction
High
Category
System Prompt Leakage
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
Content
Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.
md
### Execute Diagnosis
Method selection per mode is defined in Usage Instructions and Execution Constraints. Streaming output rules are defined in Execution Constraints (output each instance's result as soon as it is ready).
---
Direct Prompt Extraction
High
Category
System Prompt Leakage
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
Content
Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.
md
Output results **by instance dimension**, with **abnormal instances listed first**, normal instances are NOT listed individually.
**Output rules:**
- **State the diagnosis conclusion DIRECTLY** — do NOT output any "Diagnosis Complete!" style banner or preamble
- Use the method names **Console Diagnosis** and **Cloud Assistant Diagnosis** in the output; do NOT use "Channel A" / "Channel B" / "dual-channel" terminology, and do NOT display Report ID / Invoke ID / PCI slot details
- The two methods are PEER-LEVEL, and output is organized BY METHOD DIMENSION (grouped by method): a **Console Diagnosis** section listing ITS anomaly items, followed by a **Cloud Assistant Diagnosis** section listing ITS anomaly items. Console Diagnosis findings are titled by their IssueId (e.g., `GuestOS.GPU.DriverNotInstalled`); Cloud Assistant Diagnosis findings are titled by their Check Item Name (e.g., `Device Driver Install Check - Failed`). Do NOT title a Cloud Assistant finding with a Console IssueId, and vice versa; if no anomalies exist, the conclusion states the instance/instances are normal
Chaining Abuse
High
Category
Tool Misuse
Confidence
75% confidence
Finding
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Content
Scanner excerpt · references/cli-installation.md (reported line 72)May include surrounding context.
md
# macOS (manual) / Linux: re-download the latest version and overwrite
# Intel Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/
# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Chaining Abuse
High
Category
Tool Misuse
Confidence
75% confidence
Finding
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Content
Scanner excerpt · references/cli-installation.md (reported line 76)May include surrounding context.
md
# macOS (manual) / Linux: re-download the latest version and overwrite
# Intel Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/
# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Chaining Abuse
High
Category
Tool Misuse
Confidence
75% confidence
Finding
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Content
Scanner excerpt · references/cli-installation.md (reported line 80)May include surrounding context.
md
# macOS (manual) / Linux: re-download the latest version and overwrite
# Intel Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/
# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Chaining Abuse
High
Category
Tool Misuse
Confidence
75% confidence
Finding
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Content
Scanner excerpt · references/cli-installation.md (reported line 84)May include surrounding context.
md
# macOS (manual) / Linux: re-download the latest version and overwrite
# Intel Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/
# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding
The trigger language is broad enough to match common troubleshooting requests, which increases the chance that the skill is invoked in situations where the user did not intend remote command execution against instances. In this context, broad activation is more dangerous because the skill can run cloud APIs and remote instance-side commands, not just provide advice.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding
The skill supports scheduled diagnosis that creates persistent cloud-side tasks, but this consequence is not surfaced prominently in the top-level description. Users may reasonably expect a one-time diagnostic action and not realize they are authorizing recurring automation, which creates operational and security risk through persistence.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The fixed diagnostic command removes a local plugin before executing it, which is a state-changing action on the target instance rather than pure observation. Even if intended to refresh the plugin, it alters host state remotely and could disrupt existing tooling, violate least surprise, or be abused as a precedent for destructive pre-execution steps in a 'diagnosis' skill.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The skill is presented as a diagnostic capability, but it also instructs creation of persistent scheduled Cloud Assistant resources and later operational control via stop-invocation. That expands the skill from read-mostly diagnosis into infrastructure mutation, which can surprise users, create lingering automation, and increase blast radius if invoked unintentionally or by prompt confusion.
Content
No source excerpt is available for this finding.
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 17)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 31)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 72)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 76)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 80)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 84)May include surrounding context.
md
# Intel chip
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
sudo mv aliyun /usr/local/bin/
# Apple Silicon (M1/M2/M3/M4)
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding
This markdown file includes commands such as sudo mv aliyun /usr/local/bin/ and machine-level PATH modification steps that alter system state. The guide gives procedural instructions but does not explicitly warn users that these commands require elevated privileges and make system-wide changes that may affect other users or existing configurations.
Content
No source excerpt is available for this finding.
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · references/cli-installation.md (reported line 22)May include surrounding context.
The PowerShell example uses [Environment]::SetEnvironmentVariable(..., Machine) to permanently change the system PATH for the machine. The surrounding text does not warn that this is a persistent, system-level change that can impact other applications or users on the host.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Low
Category
Not specified by scanner
Confidence
98% confidence
Finding
The documentation requires output grouped by method and says Cloud Assistant findings must be titled by check item name, not Console IssueId. However, the batch output example lists per-instance findings such as 'GuestOS.GPU.DriverNotInstalled' and does not present a method-grouped Cloud Assistant section, contradicting the stated output rules.
Content
No source excerpt is available for this finding.
Static analysis
Detected: suspicious.exposed_secret_literal
File appears to expose a hardcoded API secret or token.