Back to skill

Security audit

alibabacloud-flink-python-coding

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Alibaba Cloud VVR/PyFlink coding guide that prepares local code and deployment handoff artifacts without hidden execution, credential collection, or automatic cloud actions.

Before installing, be aware that the skill may guide your agent to read Alibaba Cloud documentation, download versioned PyFlink API wheels for inspection, and create local deployment files. Review generated job examples before running them on VVR, especially any sink using overwrite, and keep real credentials in Alibaba Cloud secret variables rather than source files or README text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example writes output with mode="overwrite" to an OSS sink path, which can delete or replace existing data if the path is reused. In a deployment-oriented skill, users may copy this example directly, so the lack of an explicit warning about destructive behavior creates a real risk of accidental data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text explicitly directs users to Alibaba Cloud's Chinese documentation as the source for product knowledge. This is a natural-language locale constraint and the file does not offer an alternative language option or indicate that the user can choose their preferred documentation language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L11 directs users to the live Chinese release notes as the source for version selection. This is a natural-language locale constraint and the file does not offer an alternative language source or indicate user choice, which conflicts with the policy against forcing a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L20 says to use the Chinese release notes for release availability, again enforcing a specific locale as the canonical source. Because the document does not provide opt-in, alternatives, or a clear policy justification for this locale restriction, it fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill text links only to Chinese-language documentation (/zh/ URLs) as the primary reference for users. This can amount to a language/locale constraint in the natural-language guidance without any opt-in, alternative locale, or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.