T08 · Insecure Dependencies
- Location
references/cli-installation-guide.md:29- Finding
Unpinned and Unverified Installation of Executable Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a legitimate Alibaba Cloud ECS extension-install skill, but it combines high-impact cloud control with overbroad permissions, unsafe credential/setup guidance, and unpinned plugin updates.
Install only after reviewing the cloud permissions. Use a dedicated least-privilege RAM role or short-lived session scoped to the intended instances, avoid FullAccess policies and long-lived access keys, do not paste secrets into commands, and pin or verify CLI/plugin versions before allowing updates. Treat all installation parameters and reports as potentially sensitive.
references/cli-installation-guide.md:29Unpinned and Unverified Installation of Executable Dependencies
references/cli-installation-guide.md:79Cloud Credentials Exposed Through Command-Line Arguments
references/ram-policies.md:24Wildcard Remote-Execution Permissions and Full-Access Fallback
SKILL.md:337Predictable Temporary Files Permit Local File Attacks and Data Disclosure
The trigger phrases are broad terms like "install," "Python," and "package," which are likely to match unrelated user requests. That increases the chance that this high-impact skill is invoked in the wrong context, potentially steering an agent into cloud-instance modification workflows when the user did not intend to operate on Alibaba ECS resources.
The skill mandates enabling AI mode, setting a user agent, and running aliyun plugin update before any workflow action, including read-only queries. Automatic plugin updates modify the execution environment, introduce supply-chain/change-management risk, and expand the skill's effects beyond the user's apparent request to query or install an extension.
The skill first states that all user-customizable parameters must be explicitly confirmed, then later allows optional parameters to be applied from defaults if the user does not provide them. In an installation workflow that changes cloud instances, this inconsistency can cause the agent to proceed with unreviewed configuration values, increasing the risk of unintended software versions, insecure settings, or unexpected environment changes.
The scenario router relies on ambiguous keywords such as "list," "support," and "install," which are not constrained to Alibaba Cloud or ECS extension operations. In a skill capable of initiating instance changes, weak routing increases the risk of accidental activation and unsafe action selection from ordinary conversational language.
The skill requires saving the full --parameters JSON to /tmp and reproducing it in the installation report. Because extension-specific parameters may include secrets, tokens, license keys, or other sensitive user-supplied values, this creates a clear risk of credential leakage to local disk, logs, shell history, or user-visible output.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-macosx-latest-amd64.tgz
# Move to PATH
sudo mv aliyun /usr/local/bin/
# Verify
aliyun version
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/
### Windows
The guide shows use of long-lived Access Key credentials directly on the command line and notes they are stored in ~/.aliyun/config.json. Even though later sections mention best practices, this example normalizes persistent credential use and can lead to accidental exposure through shell history, copied snippets, shared home directories, backups, or insecure file permissions.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once
### Configuration Modes
The environment variable examples export cloud credentials without warning that environment secrets may be exposed via shell history, CI logs, crash dumps, inherited child processes, or process inspection on some systems. In an automation-oriented skill, this increases the chance users will paste secrets into unsafe contexts.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Restrict permissions
chmod 600 ~/.aliyun/config.json
The file gives a ready-to-run start-execution command that initiates software installation on ECS instances, but it does not prominently warn that this operation changes the target system state. In an agent skill context, omission of an explicit change-impact warning increases the risk of users or downstream automation triggering unintended modifications to production instances.
No suspicious patterns detected.