Back to skill

Security audit

Alibabacloud Maxcompute Migration Service

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent migration helper, but it asks for broad cloud authority and unsafe mutable CLI/plugin installation paths that users should review before installing.

Install only after reviewing the setup and permission model. Prefer a preinstalled, version-pinned Aliyun CLI from a trusted package manager, avoid auto plugin updates unless approved, use short-lived or tightly scoped credentials, and replace the broad RAM/MaxCompute grants with least-privilege policies for the exact migration scope.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:56
Finding

Unverified Remote Installer Is Executed Directly by Bash

Content
View full analysis
= 3.3.3` required**: run `aliyun version` to verify. If not installed or the version is too low: - run `/bin/bash -c "$(curl -fsSL https://aliyuncli.alicdn.com/setup.sh)"` to install or update, or - run `aliyun upgrade` (available from CLI >= 3.3.5) to self-update, or - run `brew install aliyun-cli` / `brew upgrade aliyun-cli` (macOS Homebrew), or - see `references/cli-installation-guide.md` for full installation instructions. Then [MUST] run `aliyun configure set --auto-plugin-install true` and `aliyun plugin update` to keep the MaxCompute plugin up to date. ``` ### Technical Analysis The Skill instructs the agent to download a shell script from an external URL and pass the response directly to `/bin/bash`. The retrieved content is not pinned to a specific release, stored for inspection, or authenticated with a checksum or digital signature. Consequently, the effective code executed on the host can change after the Skill package has been audited. HTTPS protects transport under ordinary conditions but does not protect against compromise of the vendor endpoint, CDN, publishing process, or signing infrastructure. Direct execution also prevents the user from reviewing the downloaded payload before it runs. This behavior is not necessary for migration management itself. Installation can be performed through a verified, version-pinned package or through an explicitly reviewed administrative process. ### Attack Path 1. A user requests an MMS operation. 2. The Skill determines that Aliyun CLI is missing or outdated. 3. The agent runs the documented Bash command. 4. The external endpoint, CDN, DNS path, or publisher account supplies a modified `setup.sh`. 5. Bash immediately executes the modified payload with the privileges o ...[truncated 661 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:24
Finding

Mutable CLI Binaries Are Installed into a Privileged PATH Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/ram-policies.md:177
Finding

Migration Documentation Recommends Excessive Administrative and Destructive Permissions

Content
View full analysis
:role/AliyunServiceRoleForMaxComputeMMS`; ``` ### 3.3 Fine-Grained Authorization **Project-level permissions:** ```sql GRANT Read,Write,List,CreateTable,CreateInstance,CreateFunction,CreateResource ON project TO USER `RAM$:role/AliyunServiceRoleForMaxComputeMMS`; -- Or grant all permissions GRANT ALL ON project TO USER `RAM$:role/AliyunServiceRoleForMaxComputeMMS`; ``` **Table-level permissions:** ```sql GRANT Describe,Select,Alter,Update,Drop,ShowHistory ON table TO USER `RAM$:role/AliyunServiceRoleForMaxComputeMMS`; -- Or grant all permissions GRANT All ON table TO USER `RAM$:role/AliyunServiceRoleForMaxComputeMMS`; ``` ``` The same document also recommends `AliyunRAMFullAccess`, `AliyunMaxComputeFullAccess`, and RAM policies using `"Resource": "*"`. ### Technical Analysis The documented authorization model exceeds the minimum privileges needed for a scoped data migration. In particular: - Project `admin` and `GRANT ALL` allow broad control unrelated to migration. - Table permissions include `Drop`, permitting destructive deletion. - Account-wide RAM administration allows modification of identities and policies. - `AliyunMaxComputeFullAccess` and wildcard resources extend access beyond the selected migration source or target. - Read-only monitoring, migration execution, mapping updates, and service-linked-role creation are not separated into distinct roles. This creates a large blast radius if the agent, CLI process, cloud identity, or local workstation is compromised. ### Attack Path 1. An operator follows the “recommended” coarse-gra ...[truncated 1046 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli-installation-guide.md:88
Finding

Installation Guide Exposes Long-Lived Access Keys Through Command Arguments and Environment Variables

Content
View full analysis
\ --access-key-secret \ --region ``` **Where to Get Access Keys** 1. Log in to Aliyun Console: https://ram.console.aliyun.com/ 2. Navigate to: AccessKey Management 3. Create a new AccessKey pair 4. Save the secret immediately — it's only shown once ### Environment Variables **Access Key Mode** ```bash export ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id export ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret export ALIBABA_CLOUD_REGION_ID= ``` ``` ### Technical Analysis The guide encourages users to place long-lived access keys directly in command arguments and shell environment variables. Command-line secrets may be retained in shell history, terminal recordings, audit logs, command wrappers, or process metadata. Exported environment variables are inherited by child processes and can be exposed through debugging output, crash reports, process inspection, or malicious local tools. This guidance directly conflicts with `SKILL.md`, which states that plaintext credentials must not be printed or persisted, and with `references/acceptance-criteria.md`, which explicitly classifies command-line credential entry as incorrect. ### Attack Path 1. A user copies the configuration example and substitutes real access keys. 2. The command is retained in shell history or captured by terminal or process-monitoring facilities. 3. Alternatively, exported secrets are inherited by an untrusted child process or tool. 4. A local attacker or compromised process extracts the access key ID and secret. 5. The attacker authenticates to Alibaba Cloud using the victim’s identity. 6. The attacker performs all ope ...[truncated 608 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/commands-job-timer-task.md:72
Finding

User-Controlled Migration Parameters Are Inserted into Shell Command Templates Without Safe Argument Construction

Content
View full analysis
\ --name \ --src-db-name \ --tables table_a table_b \ --partition-filters table_a=ds=20260101 table_b=pt=hangzhou \ --enable-schema-migration true \ --enable-data-migration true \ --enable-verification true \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-maxcompute-migration-service/{session-id} ``` Similar unquoted placeholders are used in datasource lookup, mapping update, job, task, and timer command templates. ### Technical Analysis The Skill expects the agent to substitute user-provided names and partition filter expressions into executable shell commands. It does not require use of an argument-array API, define an allowlist for identifiers, reject shell control characters, or prescribe a reliable escaping mechanism. The statement to “quote the value as needed” is insufficient because correct quoting depends on the execution API and shell. If an agent constructs one command string and passes it to a shell, values containing command separators, substitutions, redirections, newlines, or option-like prefixes may change command semantics. The confirmation gate reduces accidental migration actions but does not sanitize malicious input or prevent local command execution. ### Attack Path 1. An attacker supplies a crafted job name, database name, table name, or partition expression containing shell syntax. 2. The agent substitutes the value into a documented command template. 3. The agent executes the resulting command through a shell rather than through a structured argument API. 4. The shell ...[truncated 924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about an operational MaxCompute migration skill with workflow logic and safety constraints for migration-related commands. The supplied code does not implement any migration functionality at all. Instead, it prepares a local testing environment by creating directories, verifying SKILL.md exists, copying SKILL.md, replacing a references directory, and printing the destination path. This is a materially different primary purpose and represents unrelated filesystem synchronization behavior rather than the declared migration operations.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs the agent to fetch and execute a remote installation script via curl|bash and to enable automatic plugin installation and updates. In an agent context, this creates a software supply-chain and arbitrary code execution risk because future executions may run unreviewed code from the network or newly updated plugins without explicit user verification.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- **Aliyun CLI (first-run only) — version `>= 3.3.3` required**: run `aliyun version` to verify. If not installed or the version is too low:
  - run `/bin/bash -c "$(curl -fsSL https://aliyuncli.alicdn.com/setup.sh)"` to install or update, or
  - run `aliyun upgrade` (available from CLI >= 3.3.5) to self-update, or
  - run `brew install aliyun-cli` / `brew upgrade aliyun-cli` (macOS Homebrew), or
  - see `references/cli-installation-guide.md` for full installation instructions.
  Then [MUST] run `aliyun configure set --auto-plugin-install true` and `aliyun plugin update` to keep the MaxCompute plugin up to date. Do not repeat setup steps in normal migration workflows.

Self-Modification

High
Category
Rogue Agent
Confidence
95% confidence
Finding

The guide explicitly encourages aliyun upgrade to self-update and pairs it with a remote setup-script execution path. Self-modifying tooling that fetches and replaces executables can expand supply-chain risk, reduce change control, and undermine reproducibility, especially in enterprise or agent-operated environments where updates should be pinned and reviewed.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 7)May include surrounding context.

md
> **Aliyun CLI 3.3.3+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.3 or later for full plugin ecosystem coverage.
>
> Quickest install/update: `/bin/bash -c "$(curl -fsSL https://aliyuncli.alicdn.com/setup.sh)"`, or `aliyun upgrade` (available from CLI >= 3.3.5) to self-update.

## Installation

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/sync_qwen_skill_default_workdir.sh (reported line 24)May include surrounding context.

sh
fi

cp "${REPO_ROOT}/SKILL.md" "${TARGET_SKILL_DIR}/SKILL.md"
rm -rf "${TARGET_SKILL_DIR}/references"
if [[ -d "${REPO_ROOT}/references" ]]; then
  cp -R "${REPO_ROOT}/references" "${TARGET_SKILL_DIR}/references"
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide recommends executing a remotely fetched script directly with /bin/bash -c "$(curl ...)" and also promotes self-update behavior without any integrity verification, pinning, or warning. In a documentation file for an agent skill, this is dangerous because users may copy-paste privileged installation commands that execute unreviewed code from the network, enabling supply-chain compromise or arbitrary code execution if the host, transport, or distribution endpoint is tampered with.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 32)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 47)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 60)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 73)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs users to configure long-lived access keys via CLI arguments and environment variables but does not warn about secret handling risks such as shell history exposure, process list leakage, shared terminal logging, or committing exported values into scripts. In a migration-service context, these credentials may grant access to sensitive cloud data and infrastructure, so insecure guidance increases the chance of credential disclosure and downstream account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that migration execution starts automatically after job creation, but it does not place a prominent safety warning near the command examples about immediate data-impacting behavior. In an agent skill context, this increases the chance that an automated workflow will create and launch a migration job with real operational consequences before the user fully appreciates that creation is not a dry-run action.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/sync_qwen_skill_default_workdir.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
# Sync repo SKILL.md + references/ into the fixed qwen workdir used for manual checks.
# Layout:
#   <workdir>/.qwen/skills/alibabacloud-maxcompute-migration-service/SKILL.md
#   <workdir>/.qwen/skills/alibabacloud-maxcompute-migration-service/references/**
#
# Override workdir root:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documented stop, retry, and timer update operations can change or interrupt active migration workflows, yet they are presented as straightforward commands without adjacent cautions about production impact, scheduling changes, or service disruption. In an agent-operated setting, this omission can lead to unsafe execution of state-changing commands against live jobs and timers.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · references/ram-policies.md (reported line 199)May include surrounding context.

3.3 Fine-Grained Authorization

Project-level permissions:

sql
GRANT Read,Write,List,CreateTable,CreateInstance,CreateFunction,CreateResource

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
95% confidence
Finding

The phrase 'Or grant all permissions' normalizes use of blanket project-level authorization instead of least-privilege controls. In a migration skill, this is more dangerous because operators may copy-paste the guidance into production, giving the service role excessive reach across sensitive datasets and project operations.

Content

Scanner excerpt · references/ram-policies.md (reported line 205)May include surrounding context.

GRANT Read,Write,List,CreateTable,CreateInstance,CreateFunction,CreateResource ON project <project_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

-- Or grant all permissions GRANT ALL ON project <project_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

text

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documentation explicitly offers GRANT ALL ON project to the MMS service-linked role, which grants far more authority than is typically needed for migration. If followed, compromise or misuse of that role could lead to unrestricted project-wide data access and administrative actions, violating least-privilege and increasing blast radius.

Content

Scanner excerpt · references/ram-policies.md (reported line 209)May include surrounding context.

GRANT ALL ON project <project_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

text

**Table-level permissions:**

```sql
GRANT Describe,Select,Alter,Update,Drop,ShowHistory

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
93% confidence
Finding

The phrase 'Or grant all permissions' for tables encourages overbroad object-level privileges and can permit destructive actions beyond what migration generally needs. In the context of a data migration service, this expands the consequences of accidental actions or service-role compromise to table tampering or deletion.

Content

Scanner excerpt · references/ram-policies.md (reported line 215)May include surrounding context.

GRANT Describe,Select,Alter,Update,Drop,ShowHistory ON table <table_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

-- Or grant all permissions GRANT All ON table <table_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

text

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
92% confidence
Finding

The example GRANT All ON table encourages full control over tables, including destructive or modification-capable actions that may exceed migration requirements. If applied broadly, it enables unnecessary alteration or deletion of table assets and increases the impact of role misuse.

Content

Scanner excerpt · references/ram-policies.md (reported line 219)May include surrounding context.

GRANT All ON table <table_name> TO USER RAM$<account_id>:role/AliyunServiceRoleForMaxComputeMMS;

text

**Instance-level permissions:**

```sql
GRANT Read,Write ON instance <instance_id>

Static analysis

No suspicious patterns detected.