Back to skill

Security audit

Alibabacloud Migrate

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent cloud-migration assistant, but it can copy sensitive Terraform state data into local plaintext reports and performs more environment interaction than its code-generation-only framing suggests.

Review this skill before installing in sensitive infrastructure repos. Use it only in workspaces where Terraform state and variable files may be read, keep `.migration-report/` private and out of source control, inspect reports for secrets, and review generated Terraform carefully, especially public endpoints and any preapproval request. Expect validation to run Terraform locally and possibly require network access for provider/plugin resolution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/workflows/discovery-and-analysis.md:55
Finding

Terraform State Secrets May Be Persisted in Plaintext Migration Reports

Content
View full analysis

Vulnerability Details

File Location: references/workflows/discovery-and-analysis.md, lines 55-64, 120-128, 235, and 242-274
Vulnerability Type: Sensitive data exposure through insufficient redaction
Risk Level: High

Vulnerable Code Snippet

markdown
Scan all `.tf` and `.tfstate` files, extract every resource definition with complete configuration.

| Field | Description | Resolution |
|---|---|---|
| `id` | Resource identifier | `aws_instance.web`, `data.aws_iam_policy_document.x` |
| `type` | Resource type | `aws_instance`, `aws_vpc` |
| `discovery_method` | How the resource was found | See table below |
| `source_file` | File path where defined | `main.tf`, `modules/vpc/main.tf` |
| `region` | From provider config | Explicit `provider = aws.alias` → alias region; else default provider region |
| `properties` | Resolved attribute values | Priority: `.tfstate` attrs → `.tfvars` → non-sensitive variable defaults → preserve `var.<name>` |
| `dependencies` | Resource IDs this depends on | See dependency detection below |

The state-priority and persistence behavior is reinforced later:

markdown
`.tf` ∪ `.tfstate` → no duplicates. When both exist for same resource, `.tfstate` values take priority.
markdown
Write a single JSON object to `.migration-report/input-resources.json`.

The variable-handling rules only protect values whose source variable is explicitly marked sensitive:

markdown
Rules:

1. Resolve variables from `.tfvars` or defaults when a concrete value is available and safe to copy.
2. If a concrete value cannot be resolved, preserve resource properties as `var.<name>` and record the variable in `variables`.
3. If the source variable declares `sensitive = true`, record `sensitive: true` and propagate that flag to target Terraform variables.
4. If the source variable has no default, record `has_default: false`; missing values are not a d
...[truncated 3180 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not copy complete state attributes by default.

    • Extract only attributes explicitly required for resource mapping.
    • Maintain per-resource allowlists of migration-relevant, non-secret fields.
  2. Redact known sensitive attributes.

    • Remove values for fields such as password, secret, token, private_key, access_key, connection_string, client_secret, and similar provider-specific attributes.
    • Apply case-insensitive matching to nested object keys.
  3. Detect credential-like values independently of Terraform metadata.

    • Scan values for private-key headers, access-key formats, bearer tokens, signed URLs, and high-entropy credential strings.
    • Replace detected values with a structured marker such as:
      json
      {
        "value": null,
        "sensitive": true,
        "source": "redacted_from_state"
      }
      
  4. Treat state-derived sensitivity conservatively.

    • Do not rely only on variable.sensitive.
    • Consider provider-returned sensitive fields and unknown state fields sensitive unless an allowlist marks them safe.
  5. Preserve references instead of concrete secrets.

    • Generate sensitive Terraform variables without defaults.
    • Use secret-manager references where appropriate.
    • Never request, display, or persist the underlying value in migration reports.
  6. Protect generated artifacts.

    • Create .migration-report/ with restrictive filesystem permissions.
    • Add .migration-report/ to .gitignore.
    • Warn users not to commit, upload, or share reports until they have been reviewed for sensitive data.
  7. Add a mandatory pre-write security check.

    • Scan the complete output object before writing input-resources.json.
    • Abort or redact automatically if potential credentials are found.
    • Record only the field name and redaction reason, never the original value.
  8. **Mini ...[truncated 180 chars]

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/mappings/azure/compute.md (reported line 76)May include surrounding context.

md
admin_ssh_key {
    username   = "adminuser"
    public_key = file("~/.ssh/id_rsa.pub")
  }

  os_disk {

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/mappings/azure/compute.md (reported line 123)May include surrounding context.

md
admin_ssh_key {
    username   = "adminuser"
    public_key = file("~/.ssh/id_rsa.pub")
  }

  os_disk {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The same pre-approval logic also recognizes auto-approve, enabling the agent to interpret a broad phrase as sufficient authorization to continue. In the skill context, this is more dangerous because the generated Terraform may encode substantial infrastructure changes, so weak approval semantics increase the chance of unintended or manipulated outputs.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
**⚠️ CRITICAL**: Phases **MUST** be executed in sequential order. Each phase depends on the previous phase's output. **Never skip or reorder phases.**

**Pre-approval flag**: During Phase 1, detect whether the initial user prompt contains a pre-approval signal such as "直接生成不需要确认", "不用审批", "auto-approve", or "skip approval". Record this intent in `migration-state.json.user_confirmations`. This skips only the Phase 3 approval wait; Phase 3 must still generate `assessment-report.md` and set `approval_status: "approved"` before Phase 4.

| Phase | Input → Output | Reference |
|-------|----------------|-----------|

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The same pre-approval logic also recognizes auto-approve, enabling the agent to interpret a broad phrase as sufficient authorization to continue. In the skill context, this is more dangerous because the generated Terraform may encode substantial infrastructure changes, so weak approval semantics increase the chance of unintended or manipulated outputs.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
**⚠️ CRITICAL**: Phases **MUST** be executed in sequential order. Each phase depends on the previous phase's output. **Never skip or reorder phases.**

**Pre-approval flag**: During Phase 1, detect whether the initial user prompt contains a pre-approval signal such as "直接生成不需要确认", "不用审批", "auto-approve", or "skip approval". Record this intent in `migration-state.json.user_confirmations`. This skips only the Phase 3 approval wait; Phase 3 must still generate `assessment-report.md` and set `approval_status: "approved"` before Phase 4.

| Phase | Input → Output | Reference |
|-------|----------------|-----------|

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims to be code-generation-only, but it instructs the agent to run terraform init && terraform validate, which can trigger local command execution and provider/plugin resolution. That expands the skill from passive code generation into environment interaction, creating unnecessary execution and supply-chain exposure for a migration assistant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs the agent to output a fixed Chinese message when no Terraform files are found. This imposes a specific language on the user regardless of their preferred locale, and the file does not state that Chinese output is limited to a region-specific audience or optional.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

By mandating that the agent proceed directly to Phase 4 after detecting auto-approve-style language, the skill creates an autonomous path around the intended human approval checkpoint. In a migration skill, the surrounding context makes this riskier because outputs are operationally sensitive and may later be trusted or applied with limited review.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
**⚠️ Exception — User pre-approval in initial prompt:**

If the user's **initial migration request** contains pre-approval signals (explicit phrases like "直接生成不需要确认", "直接帮我生成不需要再问我确认", "auto-approve", "skip approval", or any equivalent instruction to bypass the approval gate), the Agent MUST:

1. Detect this intent during Phase 1 or before Phase 3
2. **Still generate** `assessment-report.md` in Phase 3 — skip only the approval wait, not the assessment artifact

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

By mandating that the agent proceed directly to Phase 4 after detecting auto-approve-style language, the skill creates an autonomous path around the intended human approval checkpoint. In a migration skill, the surrounding context makes this riskier because outputs are operationally sensitive and may later be trusted or applied with limited review.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
**⚠️ Exception — User pre-approval in initial prompt:**

If the user's **initial migration request** contains pre-approval signals (explicit phrases like "直接生成不需要确认", "直接帮我生成不需要再问我确认", "auto-approve", "skip approval", or any equivalent instruction to bypass the approval gate), the Agent MUST:

1. Detect this intent during Phase 1 or before Phase 3
2. **Still generate** `assessment-report.md` in Phase 3 — skip only the approval wait, not the assessment artifact

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation explicitly contemplates provider downloads, registry access, and network-dependent validation steps even though the skill's stated purpose is only to generate code. This broadens the trust boundary to external networks and registries, increasing attack surface through unintended egress, dependency fetching, and exposure to malicious or compromised provider artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file includes a migration checklist with imperative operational steps such as creating network resources, validating connectivity, and updating DNS TTLs. In a skill explicitly scoped to code generation only and excluding deployment, data migration, and DNS cutover, this can mislead an agent or user into treating the skill as an execution runbook, increasing the chance of unauthorized or unsafe infrastructure changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The checklist language directly implies execution of migration actions despite the manifest stating no deployment or DNS cutover. This mismatch weakens safety boundaries for downstream agents by normalizing live operational tasks, which could cause an agent to generate or recommend actions beyond approved scope, especially around networking and DNS where mistakes can disrupt production systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Function Compute trigger is configured with authType = "anonymous" and common HTTP methods, but the document does not warn that this creates an unauthenticated public endpoint. Users may copy this directly into production, exposing function execution to abuse, data leakage, denial of service, or unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ECI example enables a public IP with internet_ip = true and provides no warning or safer default. This can lead users to deploy internet-exposed container workloads unintentionally, increasing attack surface and risk of unauthorized access if the service is not hardened.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The ACK example enables internet access to the Kubernetes API server via slb_internet_enabled = true without any caution. Publicly reachable control-plane endpoints materially increase exposure to brute force, misconfiguration, and unauthorized access attempts, especially if consumers copy the example unchanged.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly includes operational migration steps such as updating DNS, migrating images/workloads, and decommissioning source resources, which exceeds the stated 'code generation only' boundary for the skill. In an agent setting, this can cause downstream behavior that encourages or automates real infrastructure changes with availability and rollback risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The AKS→ACK migration pattern says to migrate workloads using kubectl, which is operational deployment guidance rather than code-only mapping. In a migration skill, this is dangerous because it nudges the agent or user toward live cluster changes that may disrupt production workloads or bypass change-control expectations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The workflow allows the human approval gate to be bypassed whenever the system interprets the initial user prompt as a request to skip confirmation, and then automatically marks approval_status as approved. This weakens the explicit HITL checkpoint and can lead to Terraform generation for incorrect or inferred mappings without a fresh, informed review of the assessment report.

Content

Scanner excerpt · references/workflows/assessment-report.md (reported line 87)May include surrounding context.

Approve and proceed to generate Terraform code? Reply "approved" or describe changes needed.

text

**Exception**: If the user has explicitly requested to skip confirmation (e.g., "无需确认直接生成", "不用审批"), skip only the approval wait, not the assessment artifact. Still generate `assessment-report.md`, then set `approval_status: "approved"` and `current_phase: "phase3-approved"` in `.migration-report/migration-state.json` before proceeding to Phase 4.

### Required Approval State

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The exception clause gives example opt-out phrases only in Chinese ("无需确认直接生成", "不用审批") for skipping confirmation. This creates a language-specific interaction requirement in natural-language instructions without explicit opt-in or an equivalent multilingual alternative.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to run terraform fmt, terraform init, and terraform validate, which goes beyond the skill's declared 'code generation only' scope and causes local command execution on generated, partially user-influenced configuration. Even with -backend=false, terraform init can still download providers and interact with the network, creating an unnecessary execution surface and violating least-privilege expectations for a codegen skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow hard-codes a Chinese-only user-facing stop message when Terraform files are missing, without checking or honoring the user's language. In this migration-assistant context, that can confuse users, cause miscommunication at a critical confirmation gate, and lead to incorrect workflow branching or stalled analysis rather than direct system compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow explicitly instructs writing source_resource as the full Phase 1 object and propagating top-level variables metadata into .migration-report/alibabacloud-mapped-resources.json, which can preserve sensitive infrastructure details such as resource topology, source file names, regions, dependency graphs, and variable sensitivity markers. In a migration skill, these artifacts are likely to be generated and stored routinely, so the absence of any minimization, redaction, or handling guidance increases the chance of leaking internal cloud architecture or secret-related metadata through local files, logs, or downstream processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is primarily in English, but the load balancer and ALB mapping tables switch to Chinese phrases such as "通用", "推荐替代", and other Chinese descriptions. Because the file does not explain that it is intended for Chinese readers or offer a language/locale choice, it creates a natural-language locale policy inconsistency.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The workflow instructs the agent to fetch raw files from GitHub over HTTP to verify provider resource documentation. Although related to generating correct Terraform, this adds external network access capability that is not declared in the manifest, which frames the skill as producing reports and code rather than performing live remote lookups.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/mappings/azure/compute.md:185