Back to skill

Security audit

Alibabacloud Ecs Install Extension

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate Alibaba Cloud ECS extension-install skill, but it combines high-impact cloud control with overbroad permissions, unsafe credential/setup guidance, and unpinned plugin updates.

Install only after reviewing the cloud permissions. Use a dedicated least-privilege RAM role or short-lived session scoped to the intended instances, avoid FullAccess policies and long-lived access keys, do not paste secrets into commands, and pin or verify CLI/plugin versions before allowing updates. Treat all installation parameters and reports as potentially sensitive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:29
Finding

Unpinned and Unverified Installation of Executable Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/cli-installation-guide.md:79
Finding

Cloud Credentials Exposed Through Command-Line Arguments

Content
View full analysis
\ --access-key-secret \ --region cn-hangzhou ``` The guide also supplies literal credential-bearing examples: ```bash aliyun configure set \ --mode AK \ --access-key-id LTAI5tXXXXXXXX \ --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \ --region cn-hangzhou ``` ```bash aliyun configure set \ --mode StsToken \ --access-key-id LTAI5tXXXXXXXX \ --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \ --sts-token v1.0:XXXXXXXXXXXXXXXX \ --region cn-hangzhou ``` Credential rotation is documented in the same unsafe form: ```bash aliyun configure set --access-key-id NEW_KEY --access-key-secret NEW_SECRET ``` ### Technical Analysis Secrets supplied as command-line arguments may be recorded in shell history, terminal session recordings, CI/CD output, automation logs, endpoint telemetry, and audit systems. Depending on the operating system and process isolation settings, command-line arguments may also be visible to local users or monitoring agents while the process is running. These examples directly contradict the security rules in `SKILL.md:41-48`, which state that literal AK/SK values must never be passed through `aliyun configure set`. Because the referenced guide is part of the Skill and is explicitly presented as the credential setup path, users may follow the insecure examples despite the higher-level warning. ### Attack Path 1. A user follows the configuration guide and substitutes real access-key, secret-key, or STS-token values into the documented command. 2. ...[truncated 995 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/ram-policies.md:24
Finding

Wildcard Remote-Execution Permissions and Full-Access Fallback

Content
View full analysis
\ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-install-extension ``` ### Technical Analysis The documented policy combines discovery permissions with powerful write and execution actions, including `ecs:RunCommand`, `oos:StartExecution`, and `oos:UpdateInstancePackageState`, while setting `Resource` to `*`. This does not constrain the Skill to the target instances, templates, buckets, regions, or installation operation approved by the user. `ecs:RunCommand` is particularly sensitive because it can cause Cloud Assistant to execute commands on eligible ECS instances. `oos:StartExecution` can initiate orchestration templates that modify cloud resources or invoke other services according ...[truncated 1537 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:337
Finding

Predictable Temporary Files Permit Local File Attacks and Data Disclosure

Content
View full analysis
/tmp/oos-template.json ``` Installation parameters are also written to a fixed path and consumed later: ```bash # Save parameters to file for traceability cat > /tmp/oos-start-params.json << 'PARAMS_EOF' {"regionId":"【User-Provided-Region】","OOSAssumeRole":"","targets":{"ResourceIds":["【User-Provided-InstanceId】"],"RegionId":"【User-Provided-Region】","Type":"ResourceIds"},"rateControl":{"Mode":"Concurrency","Concurrency":1,"MaxErrors":0},"action":"install","packageName":"【User-Specified-Package】","parameters":【User-Provided-Parameters】} PARAMS_EOF # Execute with parameters from file aliyun oos start-execution \ --biz-region-id "【User-Provided-Region】" \ --template-name "ACS-ECS-BulkyConfigureOOSPackageWithTemporaryURL" \ --mode "Automatic" \ --tags "{}" \ --parameters "$(cat /tmp/oos-start-params.json)" \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-ecs-install-extension ``` ### Technical Analysis The workflow uses fixed filenames under the shared `/tmp` directory without secure creation, exclusive-open semantics, ownership validation, restrictive permissions, or cleanup. An attacker with local access can predict these names and may pre-create them as symbolic links or otherwise manipulate them before the workflow runs. Shell redirection follows symbolic links. As a result, writing template output to a pre-existing malicious link can overwrite a file writable by the invoking user. The parame ...[truncated 1624 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad terms like "install," "Python," and "package," which are likely to match unrelated user requests. That increases the chance that this high-impact skill is invoked in the wrong context, potentially steering an agent into cloud-instance modification workflows when the user did not intend to operate on Alibaba ECS resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill mandates enabling AI mode, setting a user agent, and running aliyun plugin update before any workflow action, including read-only queries. Automatic plugin updates modify the execution environment, introduce supply-chain/change-management risk, and expand the skill's effects beyond the user's apparent request to query or install an extension.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill first states that all user-customizable parameters must be explicitly confirmed, then later allows optional parameters to be applied from defaults if the user does not provide them. In an installation workflow that changes cloud instances, this inconsistency can cause the agent to proceed with unreviewed configuration values, increasing the risk of unintended software versions, insecure settings, or unexpected environment changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The scenario router relies on ambiguous keywords such as "list," "support," and "install," which are not constrained to Alibaba Cloud or ECS extension operations. In a skill capable of initiating instance changes, weak routing increases the risk of accidental activation and unsafe action selection from ordinary conversational language.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires saving the full --parameters JSON to /tmp and reproducing it in the installation report. Because extension-specific parameters may include secrets, tokens, license keys, or other sensitive user-supplied values, this creates a clear risk of credential leakage to local disk, logs, shell history, or user-visible output.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide shows use of long-lived Access Key credentials directly on the command line and notes they are stored in ~/.aliyun/config.json. Even though later sections mention best practices, this example normalizes persistent credential use and can lead to accidental exposure through shell history, copied snippets, shared home directories, backups, or insecure file permissions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 118)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The environment variable examples export cloud credentials without warning that environment secrets may be exposed via shell history, CI logs, crash dumps, inherited child processes, or process inspection on some systems. In an automation-oriented skill, this increases the chance users will paste secrets into unsafe contexts.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 404)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file gives a ready-to-run start-execution command that initiates software installation on ECS instances, but it does not prominently warn that this operation changes the target system state. In an agent skill context, omission of an explicit change-impact warning increases the risk of users or downstream automation triggering unintended modifications to production instances.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.