Back to skill

Security audit

Alibabacloud Ecs Gpu Diagnosis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Alibaba Cloud ECS GPU diagnostic helper that uses the Alibaba Cloud CLI for expected instance checks and diagnosis APIs.

Install only if you intend to let an agent use your Alibaba Cloud CLI credentials for ECS diagnostics. Review the RAM permissions, prefer least-privilege credentials, verify the CLI download source, and be aware that the installation/update steps can modify a system-wide CLI binary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Chaining Abuse

High
Category
Tool Misuse
Content
# macOS (manual) / Linux: re-download the latest version and overwrite
# Intel Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz
tar -xzf aliyun-cli-macosx-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/

# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
Confidence
22% confidence
Finding
&& sudo

Chaining Abuse

High
Category
Tool Misuse
Content
# Apple Silicon Mac
wget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-arm64.tgz
tar -xzf aliyun-cli-macosx-latest-arm64.tgz && sudo mv aliyun /usr/local/bin/

# Linux x86_64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
Confidence
22% confidence
Finding
&& sudo

Chaining Abuse

High
Category
Tool Misuse
Content
# Linux x86_64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
tar -xzf aliyun-cli-linux-latest-amd64.tgz && sudo mv aliyun /usr/local/bin/

# Linux ARM64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz
Confidence
22% confidence
Finding
&& sudo

Chaining Abuse

High
Category
Tool Misuse
Content
# Linux ARM64
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz
tar -xzf aliyun-cli-linux-latest-arm64.tgz && sudo mv aliyun /usr/local/bin/

# Windows PowerShell
Invoke-WebRequest -Uri "https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip" -OutFile "aliyun-cli.zip"
Confidence
22% confidence
Finding
&& sudo

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal