Back to skill

Security audit

Alibabacloud Hologres Instance Manage

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Hologres read-only purpose is clear, but its setup instructions ask users to run mutable remote installers, change persistent CLI plugin behavior, and handle cloud credentials in risky ways.

Review before installing. Use only a verified, already installed Aliyun CLI when possible; avoid curl-to-bash setup, avoid blanket plugin updates, avoid enabling persistent automatic plugin installation, and do not paste long-lived access-key secrets into agent-visible commands or logs. Prefer least-privilege RAM roles or short-lived credentials scoped to Hologres read-only access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:20
Finding

Unverified Remote Installation Script Is Piped Directly into Bash

Content
View full analysis
= 3.3.3 required** > Run `aliyun version` to verify >= 3.3.3. If not installed or version too low, > run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to update, > or see `references/cli-installation-guide.md` for installation instructions. **Pre-check: Aliyun CLI plugin update required** > [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > [MUST] run `aliyun plugin update` to ensure that any existing plugins are always up-to-date. ```bash curl -fsSL --connect-timeout 4 --max-time 120 https://aliyuncli.alicdn.com/setup.sh | bash aliyun version ``` ``` ### Technical Analysis The installation command sends content retrieved from an external URL directly to Bash. There is no intermediate review, version pinning, cryptographic signature verification, or checksum validation. The effective code executed by the Skill can therefore change after the Skill package has been reviewed. HTTPS protects the connection in transit but does not establish that the mutable script remains safe. Compromise of the hosting infrastructure, CDN, publishing account, DNS/TLS trust path, or upstream release process could replace the script with arbitrary shell commands. The standalone command at line 30 also appears unconditional, even though the preceding text states installation is only necessary when the CLI is absent or below version 3.3.3. Installation and arbitrary shell execution are not inherently required to perform the declared read-only Hologres queries when a suitable CLI is already available. ### Attack Path 1. A user or Agent loads the Skill to list or inspect Hologres instances. 2. The Skill instructs the Agent to execute the mandatory installation sequence. 3. An attack ...[truncated 1251 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:25
Finding

Mandatory Automatic Plugin Installation and Unpinned Global Plugin Updates

Content
View full analysis
[MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > [MUST] run `aliyun plugin update` to ensure that any existing plugins are always up-to-date. ``` ### Technical Analysis The Skill requires enabling persistent automatic plugin installation and updating all existing plugins. It does not pin the required Hologram plugin to a reviewed version, verify package signatures or checksums, or limit the update to a dependency required by this Skill. This introduces a mutable supply-chain boundary into every CLI command. Enabling automatic installation also changes persistent Aliyun CLI configuration, so future commands may install remote components without a separate approval step. Updating every existing plugin broadens the change beyond the Skill's declared Hologres functionality and may replace unrelated components already installed in the user's environment. These operations exceed minimum privilege and change scope. Read-only Hologres queries only require an already installed compatible CLI and the exact product support necessary to issue those queries; they do not require globally updating unrelated plugins. ### Attack Path 1. The user or Agent follows the Skill's mandatory pre-check instructions. 2. `--auto-plugin-install` is enabled persistently. 3. `aliyun plugin update` contacts the configured plugin distribution service and resolves mutable current releases. 4. An attacker compromises the plugin repository, a plugin publisher, a release artifact, or the dependency delivery path. 5. The CLI installs or updates the compromised plugin without a Skill-pinned version or documented independent integrity check. 6. The compromised component executes when the co ...[truncated 720 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:41
Finding

Mutable “Latest” CLI Artifacts Are Installed into System-Wide Executable Paths Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli-installation-guide.md:102
Finding

Access-Key Secrets Are Passed Through Command-Line Arguments and Documented as Plaintext Configuration

Content
View full analysis
\ --access-key-secret \ --region cn-hangzhou ``` The guide also documents the resulting plaintext configuration structure: ```json { "current": "default", "profiles": [ { "name": "default", "mode": "AK", "access_key_id": "LTAI5tXXXXXXXX", "access_key_secret": "8dXXXXXXXXXXXXXXXXXXXXXXXX", "region_id": "cn-hangzhou", "output_format": "json", "language": "en" } ] } ``` ### Technical Analysis Passing long-lived access keys through command-line arguments can expose them through shell history, terminal capture, process inspection, CI/CD logs, Agent transcripts, or command auditing. The guide additionally explains that credentials are stored in `~/.aliyun/config.json`, creating a plaintext secret-at-rest concern if file permissions, backups, or host access are not adequately controlled. This guidance conflicts with the main Skill's security rules in `SKILL.md` lines 41–45, which state that the Skill must never ask for or directly handle AK/SK values. Because the installation guide is explicitly linked as the alternative setup procedure, users or Agents may follow instructions that violate the primary security boundary. The guide does later recommend `chmod 600`, but that does not mitigate exposure through command arguments, history, logs, or an already compromised user account. ### Attack Path 1. A user lacks a valid Aliyun CLI profile and opens the linked installation and configuration guide. 2. The user substitutes real access-key values into the documented command. 3. The shell records the command in histor ...[truncated 1327 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to fetch a remote script and immediately execute it with bash, which creates a supply-chain and remote code execution risk if the server, CDN, transport, or script content is compromised. The risk is heightened because the instruction is framed as a required setup step, increasing the chance an agent or user will run it without independent verification.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
**Pre-check: Aliyun CLI >= 3.3.3 required**
> Run `aliyun version` to verify >= 3.3.3. If not installed or version too low,
> run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to update,
> or see `references/cli-installation-guide.md` for installation instructions.

**Pre-check: Aliyun CLI plugin update required**

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This explicit command downloads setup.sh from an external host and pipes it straight into bash, enabling arbitrary code execution in the current environment. In a credentialed cloud-management context, compromise of that script could lead to theft of cloud credentials, execution of malicious CLI plugins, or broader host compromise.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

[MUST] run aliyun plugin update to ensure that any existing plugins are always up-to-date.

bash
curl -fsSL --connect-timeout 4 --max-time 120 https://aliyuncli.alicdn.com/setup.sh | bash
aliyun version

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash pipeline is dangerous because it removes any opportunity to validate the downloaded content before execution and directly turns network input into shell commands. In this skill's context, that could be exploited to run attacker-controlled code on systems that may already have Alibaba Cloud credentials available through the default credential chain.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

[MUST] run aliyun plugin update to ensure that any existing plugins are always up-to-date.

bash
curl -fsSL --connect-timeout 4 --max-time 120 https://aliyuncli.alicdn.com/setup.sh | bash
aliyun version

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest-style description lists generic triggers such as "list instances" and "get instance details" without limiting context to Alibaba Cloud, Hologres, or a specific invocation surface. These phrases are broad enough to collide with common user requests about many unrelated systems, which can cause unintended skill activation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
| [references/ram-policies.md](references/ram-policies.md) | Required RAM permissions |
| [references/related-commands.md](references/related-commands.md) | Complete CLI commands reference |
| [references/verification-method.md](references/verification-method.md) | Success verification steps |
| [Hologres API Documentation](https://api.aliyun.com/api/Hologram/2022-06-01/ListInstances) | Official API documentation |

## Error Handling

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
| [references/ram-policies.md](references/ram-policies.md) | Required RAM permissions |
| [references/related-commands.md](references/related-commands.md) | Complete CLI commands reference |
| [references/verification-method.md](references/verification-method.md) | Success verification steps |
| [Hologres API Documentation](https://api.aliyun.com/api/Hologram/2022-06-01/ListInstances) | Official API documentation |

## Error Handling

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document provides explicit examples for configuring long-lived Access Key credentials and shows them being stored in ~/.aliyun/config.json, but the warning about credential sensitivity and persistence risk is weak and comes much later. In an automation/agent setting, this normalizes durable credential storage on disk, which can lead to credential theft from local compromise, logs, backups, or reused environments.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 118)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 404)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide ends by encouraging installation of broad Alibaba Cloud product plugins such as ECS, VPC, RDS, and FC, which materially expands the capability surface beyond the skill's declared Hologres instance read-only purpose. In an agent skill context, bundling unrelated service exploration increases the chance of overbroad access, accidental misuse, or later prompt-driven abuse against additional cloud services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.