Back to skill

Security audit

alibabacloud-lingjun-cluster-scaling

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it can drive high-impact Alibaba Cloud changes while relying on incomplete runtime assets and weak local handling of sensitive operation data.

Install only if you are comfortable granting the agent Alibaba Cloud permissions that can alter or purchase infrastructure. Use least-privilege RAM policies, prefer temporary credentials, avoid entering reusable node login passwords, and treat this package as needing publisher fixes before production use because key runtime files are missing and local secret/state handling is weak.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/scripts.md:53
Finding

Plaintext login passwords can be exposed through insecure mutation dump files

Content
View full analysis

Vulnerability Details

File Location: references/scripts.md, lines 53–89 and 105–122
Vulnerability Type: Insecure temporary-file handling and ineffective secret redaction
Risk Level: Medium

Complete Code Snippet

bash
SAFE_MUTATE_DIR="${SAFE_MUTATE_DIR:-/tmp/lingjun-mutate}"
mkdir -p "$SAFE_MUTATE_DIR"

safe_mutate() {
  local action="${1:?action name required, e.g. extend-cluster}"
  shift

  local intent=""
  if [ "${1:-}" = "--intent" ]; then
    intent="${2:?--intent value required, e.g. --intent \"extend my cluster\"}"
    shift 2
  fi

  case "$action" in
    extend-cluster|shrink-cluster|delete-node|delete-hyper-node|\
    change-node-group|create-node-group|update-node-group|delete-node-group|\
    create-instance) ;;
    *) echo "❌ safe_mutate applies only to mutating actions; got: $action" >&2; return 2 ;;
  esac

  local args_json hash
  args_json=$(printf '%s\n' "$@" | jq -R . | jq -s .)
  hash=$(printf '%s|%s' "$action" "$args_json" | sha256sum | cut -c1-12)

  local dump="$SAFE_MUTATE_DIR/${action}-${hash}.json"
  printf '%s' "$args_json" | \
    jq --arg action "$action" --arg hash "$hash" --arg intent "$intent" \
       '{action:$action, hash:$hash, intent:$intent, args:., redacted:false}' \
    | sed -E 's/(LoginPassword"[^"]*")[^,}]*"[^"]*"/\1"******"/g; s/(--login-password"[^,}]*")[^,}]*"[^"]*"/\1"******"/g' \
    > "$dump"

  echo "$hash"
  return 0
}

safe_mutate_confirm() {
  local hash="${1:?hash required}"
  local dump
  dump=$(ls -1 "$SAFE_MUTATE_DIR"/*-"$hash".json 2>/dev/null | head -1)
  if [ -z "$dump" ] || [ ! -f "$dump" ]; then
    echo "❌ confirm submission failed: token invalid or expired" >&2
    return 2
  fi

  local action
  action=$(jq -r .action "$dump")

  local -a argv
  while IFS= read -r line; do argv+=("$line"); done < <(jq -r '.args[]' "$dump")
  safe_aliyun "${argv[@]}"
  local rc=$?

  rm -f "$dump"
  return $rc
}

Technical Analysis

The documented mutation wrapper serializes every c ...[truncated 3277 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use a private, per-user temporary directory

    • Create it with mktemp -d under a user-private runtime directory.
    • Set umask 077 before creating any state.
    • Verify that the directory is owned by the current effective UID and has mode 0700.
    • Do not reuse a pre-existing shared directory without ownership and permission validation.
  2. Enforce restrictive file permissions

    • Create dump files atomically with mode 0600.
    • Reject symbolic links and unexpected existing paths.
    • Avoid ordinary shell redirection into attacker-influenced or shared locations.
  3. Do not persist authentication secrets

    • Store only non-sensitive confirmation metadata and a digest of the authorized parameter set.
    • Keep passwords in memory for the shortest possible duration.
    • If cross-turn secret persistence is unavoidable, use an OS-backed secret store or authenticated encryption with a key unavailable to other users.
  4. Replace regular-expression redaction

    • Parse known JSON-bearing arguments with jq and recursively replace secret fields before writing them.
    • Handle separate options such as --login-password by redacting the following argument before serialization.
    • Maintain an explicit allowlist of safe fields rather than attempting to detect every secret name after serialization.
    • Add regression tests for nested JSON, escaped strings, separate flag/value pairs, arrays, and malformed input.
  5. Guarantee cleanup

    • Install cleanup traps for EXIT, INT, TERM, and error paths.
    • Delete pending state when the user cancels or confirmation expires.
    • Apply a short expiration period and securely remove stale dumps at startup.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code does not implement cluster scaling, node group creation/update, or node migration against Alibaba Cloud Lingjun. Instead, it is deployment/maintenance tooling for the skill itself. Its primary purpose is local file synchronization and validation of installed skill copies, which is materially different from the declared operational cloud-cluster management purpose. This is a clear description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
> Detailed rule explanations → [references/detailed-rules.md](references/detailed-rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
> Detailed rule explanations → [references/detailed-rules.md](references/detailed-rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
> Detailed rule explanations → [references/detailed-rules.md](references/detailed-rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
> Detailed rule explanations → [references/detailed-rules.md](references/detailed-rules.md)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
88% confidence
Finding

The instruction to treat tool stdout as the final reply and relay it verbatim creates a direct prompt/output injection channel from tool output into the user-visible response. If any underlying script, CLI output, server-returned field, or compromised dependency emits misleading instructions, secrets, or adversarial text, the agent is told to forward it without sanitization or contextual filtering.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
**Region mapping**: `Dubai=me-east-1` / `Ulanqab=cn-wulanchabu` / `Shanghai=cn-shanghai` / `Beijing=cn-beijing` / `Zhangjiakou=cn-zhangjiakou` / others → [references/supported-regions.md](references/supported-regions.md)

**Output rule**: stdout (skip `===HITL_STATUS===` blocks) IS the final reply; agent reply = one intro sentence + stdout verbatim, zero additional thinking or reformatting. Verbatim means the raw values survive: **never** drop or translate away MachineType / ClusterId / ClusterName / NodeGroupId / NodeId / OperatingState.

**Cluster name shorthand**: when user provides cluster name (not starting with 'i') → replace `--cluster-id <C>` with `--cluster-name <NAME>` in all commands

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
| [edge-cases.md](references/edge-cases.md) | Edge case handling |

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/detailed-rules.md (reported line 253)May include surrounding context.

md
## Core Workflow — Full Rules <a id="core-workflow"></a>

### HITL Chinese Display Rules (MANDATORY) <a id="hitl-chinese-display"></a>

> **Scope**: all HITL interaction copy the user **directly sees** — including `hitl_prompt:` in [`../workflows/<biz>/schema.yaml`](../workflows/README.md), merged forms, HITL summaries, and dangerous-operation warning boxes. **Not applicable to**: CLI command bodies, `--flag` names, JSON keys, API doc links, `field:` / `forbidden_inference:` / `forbidden_cli_flags:` anchor field values in yaml, `safe_aliyun` debug logs (these are the "CLI truth context" and must stay English so they can be cross-checked against CLI --help / OpenAPI error codes / sibling yaml anchors).
>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The instruction to unconditionally remove a persistent state file in the user's home directory gives the agent authority to modify local filesystem state outside the immediate business action. If abused or triggered incorrectly, this can erase compliance/interlock state and bypass cross-session safeguards intended to force human review after violations or incomplete operations.

Content

Scanner excerpt · references/detailed-rules.md (reported line 333)May include surrounding context.

md
> **Session-entry hard rule** — at the start of every session (before sending any reply), the Agent **must** check whether `$HOME/.lingjun/hitl-required.json` exists.

1. **File exists** → the Agent **must immediately** perform the HITL disclosure per the `hitl_required` field in the file (① the action corresponding to the original intent ② why it cannot be executed ③ candidate actions for the user to choose). It must **not** be skipped, and no other operation may run first. The file provides context such as `violation_code` / `user_utterance` / `attempted_action` / `conflicting_mappings`; the Agent should compose the user-facing disclosure copy based on these fields (dumping raw JSON structure is forbidden).
2. **After disclosure completes + the user has made a choice** → the Agent executes `rm -f $HOME/.lingjun/hitl-required.json` to clean up the file, then continues the flow per the user's choice.
3. **File does not exist** → normal flow, no extra action.
4. **Persistent across sessions** — the file lives in `$HOME/.lingjun/` (same directory as `pending-tasks.json`) and does not disappear when the session ends.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/detailed-rules.md (reported line 389)May include surrounding context.

md
1. All completion reports **must** be strictly generated from real CLI-returned JSON. Critical fields like `TaskId` / `RequestId` / `OrderId` / `NodeId` / `HyperNodeId` / `NodeCount` / `TaskState` / `OperatingState` must come from real API response bodies and **must not** be stitched together, guessed, or reused from historical context.
2. When a core API was not successfully called or returned failure, the report **must** mark "not executed" or "execution failed" and emit a complete failure analysis per [Edge Cases §6](edge-cases.md).
3. **Strictly forbidden**: using mocks / placeholders to impersonate real return values; hard-coding `TaskId`/`RequestId`/`OrderId`; fabricating `NodeCount` / `TaskState` transitions; producing "polling logs / progress bars / monitoring scripts / timestamps" that lack real API backing.
4. **Strictly forbidden to fabricate labels / categories for API response fields** — When a field returned by the API does not carry a classification label, the Agent is **strictly forbidden** from inferring one and presenting it to the user. Full display rules: [node-operations.md §Networks field display hard rule](../workflows/node-operations/node-operations.md).

**Execution-state annotation**: Each mutating-operation report must be tagged with one of: ✅ **Executed successfully** / ⏳ **Submitted, pending poll** / ❌ **Execution failed** / ⏸ **Not executed**.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The skill instructs the agent to create and remove state files under $HOME/.lingjun/, including rm -f $HOME/.lingjun/hitl-required.json, without describing path hardening, ownership checks, or symlink protections. In hostile local environments, that pattern can be abused to overwrite or delete unintended files via symlink/path manipulation, and it also normalizes direct file-system mutation by the agent based on conversational state.

Content

Scanner excerpt · references/edge-cases.md (reported line 396)May include surrounding context.

md
- V6 — all node-group field authorizations obtained in HITL with "skip = use default" wording are uniformly voided; if `create-node-group` / `update-node-group` already persisted, immediately run `describe-node-group` for each template field (`SystemDisk` / `DataDisk` / `LoginPassword` / `KeyPairName`) to verify whether the template is empty, disclose the real persisted state to the user, and let the user decide whether to backfill the template via `update-node-group` or delete the node group.
   - V7 — three differentiated handling paths by occurrence timing (**premise**: the Skill has no shell-level physical gate; detection relies entirely on Agent self-check — see [detailed-rules.md §Intent → Action Extended](detailed-rules.md#intent-action-extended)):
     - **V7-A** (detected at the self-check stage, the best interception point): in the [intent self-check block] **before** generating the mutating command, the Agent detects that the user-original-word keyword mapping is inconsistent with the action about to execute; at this point `safe_mutate` has **not yet been called**, the parameter confirmation table has **not been shown**, and the CLI has **not actually been issued** — there is **nothing to void** (no violation intermediate artifacts exist); the only actions are: ① the **Agent proactively** runs `jq -n '{...}' > $HOME/.lingjun/hitl-required.json` (schema in [detailed-rules.md §HITL State File Check](detailed-rules.md#hitl-state-file-check)); ② return to HITL and disclose the three things per the V7 restart entry (original-intent action / blocking reason / candidate-action two-way choice).
       - **Cross-session reminder**: the hitl-required.json written after the previous session's self-check failure persists until it is detected and cleaned up in this session. At every round entry the Agent **must** check its existence (see [SKILL.md §HITL State File Check](../SKILL.md#hitl-state-file-check-mandatory)); if it exists, HITL disclosure is mandatory and cann
...[truncated 26 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/edge-cases.md (reported line 624)May include surrounding context.

RequestId: 7B2A4F3D-8E1C-5A6D-B9F2-1C3E5A7B9D0E

text

### 6.3 Output rules

- Never echo secrets. `******` is the only allowed placeholder.
- Keep the first line to a one-sentence summary that a user can act on.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file includes direct delete-vswitch and delete-vpc commands in a skill whose declared scope is cluster scaling, expanding the operational blast radius into destructive network teardown. Even though the text says not to auto-delete shared resources, including runnable deletion guidance in-skill increases the chance an agent or operator executes irreversible network-impacting actions under the wrong context.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/scripts.md (reported line 977)May include surrounding context.

./verify-operation.sh delete cn-wulanchabu
i116913051663373010974
i159809891662373011030

text

---

## Script Installation

To install all scripts:

```bash
# Create scripts directory
mkdir -p ~/lingjun-scripts
cd ~/lingjun-scripts

# Download or copy scripts
# (Copy the script contents from above into individual files)

# Make all scripts executable
chmod +x *.sh

# Add to PATH (optional)
echo 'export PATH="$HOME/lingjun-scripts:$PATH"' >> ~/.bashrc
source ~/.bashrc

Script Best Practices

  1. Always use set -euo pipefail for error handling
  2. Validate input parameters before executing
  3. Use meaningful variable names for clarity
  4. Add comments to explain complex logic
  5. Log operations with timestamps
  6. Exit with appropriate codes (0 for success, non-zero for errors)
  7. Use colors for better readability (but check if terminal supports it)
  8. Implement timeout handling for long-running operations
  9. Clean up temporary files on

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad phrases like "node group," "change group," "add nodes," and "remove nodes," which can match unrelated infrastructure conversations and spuriously activate a mutating cloud-operation skill. In this context, accidental activation is more dangerous because the skill is designed to perform high-impact cluster and node-group changes once routed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation criteria are written broadly around mentions of creating or moving node groups, without strong boundaries distinguishing requests for explanation, planning, or unrelated systems. Because this skill governs infrastructure mutations, overbroad routing increases the chance of the agent entering a dangerous workflow from ambiguous user text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language policy violations apply to all file types. This rule hard-codes locale behavior based on text detection, which forces a language/locale decision without explicit user choice or documented opt-in.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
**Interaction model (2026-08-20)**: ALL platforms (incl. Qoder IDE) = markdown text form + text backfill (`extend_submit --user-utterance` passes the user's VERBATIM reply; do not rewrite/summarize it). Successful text-backfill parsing ≠ confirmation — phase 1 always emits an rc=3 confirmation receipt (script-level hard gate, L14); phase 2 submits only after the user explicitly confirms. Widget rendering is BANNED: never call genui.show_widget, never set LJ_WIDGET=1, never reference form.html.

**Node-type default (2026-08-23)**: expand requests that do NOT explicitly say hyper nodes default to **regular nodes** — omit `--node-type` and proceed directly to the form. NEVER ask the user to choose between regular nodes / hyper nodes. Only pass `--node-type hyper` when the user explicitly mentions hyper nodes.

**Region mapping**: `Dubai=me-east-1` / `Ulanqab=cn-wulanchabu` / `Shanghai=cn-shanghai` / `Beijing=cn-beijing` / `Zhangjiakou=cn-zhangjiakou` / others → [references/supported-regions.md](references/supported-regions.md)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The reference to lib/query-zh.sh indicates a Chinese-specific locale/language path in the skill materials, but this file does not offer a user language choice or explain a justified region-specific constraint. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 34)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 49)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 62)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 75)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide provides credential-setting commands using access key ID and secret before clearly warning that these values are highly sensitive and may be stored persistently in shell history or CLI config files. In an agent-assisted or copy/paste workflow, this increases the chance of credential disclosure, long-lived secret persistence, or accidental reuse on shared systems.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 122)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Static analysis

No suspicious patterns detected.