Back to skill

Security audit

alibabacloud-lindorm-agent-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate Lindorm operations guide, but it needs Review because it mixes real cloud mutation authority with unsafe or contradictory credential, install, and permission-management examples.

Install only if you are comfortable with an agent helping operate Alibaba Cloud Lindorm resources. Before use, require human approval for any create, scale, release, billing, whitelist, security-group, user, or permission change; do not paste access keys or passwords into chat or shell history; avoid curl-to-shell install commands; and prefer private/TLS-protected endpoints for credentials and model inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/01-dev/ai-guide.md:8
Finding

Lindorm credentials transmitted over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: references/01-dev/ai-guide.md:8-23
Vulnerability Type: Cleartext transmission of reusable credentials
Risk Level: High

Vulnerable Code

markdown
| Network type | Endpoint example | Applicable environment |
|--------------|------------------|-------------------------|
| VPC private network | `<instance_id>-proxy-ai-vpc.lindorm.aliyuncs.com:9002` | Search pipelines, ECS, and services inside the VPC |
| Public network | `<instance_id>-proxy-ai-pub.lindorm.aliyuncs.com:9002` | Local computers or public-network clients |

Before making public-network calls, confirm that the public endpoint of the AI engine is enabled and that the IP whitelist is configured.

### Connectivity check for port 9002

```bash
curl --connect-timeout 10 -m 60 \
  -H 'Content-Type: application/json' \
  -H 'x-ld-ak: <username>' \
  -H 'x-ld-sk: <password>' \
  -XPOST "http://<ai_endpoint>:9002/dashscope/compatible-mode/v1/embeddings" \
text

The same insecure pattern is repeated for model requests at lines 49-53, 87-91, 132-136, 184-188, and 230-234.

### Technical Analysis

The guide instructs users to authenticate using a Lindorm username and password in the `x-ld-ak` and `x-ld-sk` HTTP headers. It then sends those headers to an `http://` URL without TLS.

This workflow explicitly supports public endpoints for clients outside the VPC. When used over a public or otherwise untrusted network, HTTP provides neither confidentiality nor server authentication. An on-path attacker can inspect the request and recover the reusable Lindorm credentials. The attacker may also modify requests or responses in transit.

The instruction at line 272 not to include passwords in reports only prevents output disclosure; it does not protect credentials during network transmission. Likewise, an IP whitelist restricts which clients may connect but does not encrypt traffic or prevent an on-path observer from reading the headers.

### Attack Path

1.
...[truncated 1284 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS with certificate verification for every public AI endpoint example:

    bash
    curl --fail --show-error \
      --proto '=https' \
      --tlsv1.2 \
      -H 'Content-Type: application/json' \
      -H "x-ld-ak: ${LINDORM_USERNAME}" \
      -H "x-ld-sk: ${LINDORM_PASSWORD}" \
      -X POST "https://<ai_endpoint>:<tls_port>/dashscope/compatible-mode/v1/embeddings"
    
  2. If the native service on port 9002 does not support TLS, explicitly prohibit direct public-network use. Require one of:

    • A private VPC endpoint;
    • A trusted VPN or private connection;
    • An authenticated TLS reverse proxy or gateway that terminates TLS securely.
  3. Remove examples that place literal passwords directly in shell command arguments. Load credentials from a protected secret store, restricted credential file, or environment supplied by a secrets manager.

  4. Add a mandatory transport-security warning stating that IP allowlisting is not a substitute for encryption.

  5. Update all repeated plaintext examples in this file, including lines 49-53, 87-91, 132-136, 184-188, and 230-234.

  6. Rotate any credentials previously used over plaintext public connections and review relevant access logs for unauthorized activity.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (92)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
│ ├── DDL / write / query examples → references/01-dev/quick-start-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
│ ├── DDL / write / query examples → references/01-dev/quick-start-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
│ ├── SQL connection & SQL-based application development → references/01-dev/sql-client-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
│ ├── SQL connection & SQL-based application development → references/01-dev/sql-client-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
│ ├── SQL connection & SQL-based application development → references/01-dev/sql-client-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
│ ├── Graph engine usage (Gremlin / Schema / query) → references/01-dev/graph-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
│ ├── Graph engine usage (Gremlin / Schema / query) → references/01-dev/graph-guide.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
│ ├── Instance write ops (create / scale / release / pay-type) → references/02-ops/instance-lifecycle.md

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/01-dev/quick-start-guide.md (reported line 86)May include surrounding context.

md
[Step 1: Add Maven dependency]

<!-- MySQL protocol JDBC, recommended -->
<dependencies>
    <dependency>
        <groupId>com.mysql</groupId>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The embedding pipeline examples explicitly configure transmission of user text plus service credentials to a remote AI endpoint over HTTP, but the guide does not warn about data disclosure, credential exposure, or transport security requirements. In a skill context, users may copy these commands directly, causing sensitive content and passwords to traverse internal or external networks without adequate protection or informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file declares a safety boundary that the agent must not directly create users or change permissions, but then provides detailed agent responses and executable SQL for CREATE USER, GRANT, REVOKE, DROP USER, and ALTER USER. This contradiction can cause downstream agents to facilitate privileged identity and access management changes, increasing the risk of unauthorized access, privilege escalation, account deletion, or lockout.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file starts with an agent note explicitly forbidding use of aliyun configure set with literal credentials, but then provides repeated command examples that do exactly that, including realistic AK/SK placeholders and config-file storage. In an agent-skill context, this contradiction is dangerous because an automated agent may mirror the unsafe examples into chat output, shell history, logs, or persisted config, causing credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide includes executable commands and JSON examples that place access keys and secrets directly on the command line and show them persisted in ~/.aliyun/config.json, without a prominent warning about shell history, terminal logging, shared transcripts, or config-file exposure. In a skill intended for agent-assisted use, this materially increases the chance that secrets are echoed back to users or retained in system artifacts.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/03-ref/lindorm-cli-guide.md (reported line 107)May include surrounding context.

md
else
  echo "lindorm-cli installed at /tmp/lindorm-cli"
fi
rm -f /tmp/lindorm-cli.tar.gz

# Verify installation result.
lindorm-cli --version || /tmp/lindorm-cli --version

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The document instructs users to execute a remote install script directly via 'curl ... | sh' and similarly suggests PowerShell 'iex' execution. In an agent skill context, this is dangerous because it enables arbitrary code execution from a network source without pinned content review at execution time; compromise of the hosting bucket, DNS, TLS termination, or the script itself would immediately compromise the local environment and any accessible credentials.

Content

Scanner excerpt · references/03-ref/related-commands.md (reported line 24)May include surrounding context.

md
>
> ```bash
> # Linux / macOS
> curl -fsSL https://lindorm-open-api-cli.oss-cn-hangzhou.aliyuncs.com/scripts/install.sh | sh
> export PATH="$HOME/.lindorm-open-api-cli/bin:$PATH"
> # Windows (PowerShell)
> #   irm https://lindorm-open-api-cli.oss-cn-hangzhou.aliyuncs.com/scripts/install.ps1 | iex

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The explicit shell chaining operator '| sh' turns remotely fetched content into immediate command execution, eliminating any review barrier and amplifying supply-chain risk. Within a skill that may be consulted or operationalized by agents, this pattern is especially risky because it normalizes unsafe execution of external content and could be copied into privileged automation or CI environments.

Content

Scanner excerpt · references/03-ref/related-commands.md (reported line 24)May include surrounding context.

md
>
> ```bash
> # Linux / macOS
> curl -fsSL https://lindorm-open-api-cli.oss-cn-hangzhou.aliyuncs.com/scripts/install.sh | sh
> export PATH="$HOME/.lindorm-open-api-cli/bin:$PATH"
> # Windows (PowerShell)
> #   irm https://lindorm-open-api-cli.oss-cn-hangzhou.aliyuncs.com/scripts/install.ps1 | iex

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill scope includes instance creation, scaling, release, backup, migration, whitelist changes, and permission management, all of which can affect cost, availability, or access. Although some command examples later note confirmation behavior, the top-level skill description does not clearly warn users that the skill may guide destructive or billable actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented whitelist, security-group, billing-mode switch, and release commands can cause immediate lockout, service disruption, or irreversible deletion if surfaced to users without a strong warning and preflight guardrail. Although the skill mentions confirmation and some command semantics, it does not require a user-facing disruption warning or backup/rollback validation immediately adjacent to these high-risk operations, which increases the chance of accidental harmful execution in an agent workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/01-dev/ai-guide.md (reported line 19)May include surrounding context.

Connectivity check for port 9002

bash
curl --connect-timeout 10 -m 60 \
  -H 'Content-Type: application/json' \
  -H 'x-ld-ak: <username>' \
  -H 'x-ld-sk: <password>' \

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/01-dev/graph-guide.md:668