Back to skill

Security audit

Alibabacloud Network Alb Http To Https

Security checks for vulnerabilities and agentic risk

Overview

The ALB redirect workflow is mostly coherent, but the skill asks users to run mutable remote installers and handles TLS private keys in ways that deserve careful review.

Install only if you are comfortable reviewing and controlling the Aliyun CLI and plugin installation yourself. Prefer verified, pinned CLI/plugin versions, avoid curl-to-bash and unverified latest downloads, use least-privilege RAM permissions, and do not use the bundled certificate helpers with production private keys unless the key-handling issues are fixed or otherwise mitigated.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:31
Finding

Unverified Remote Installer Executed Directly Through Bash

Content
View full analysis
**Pre-check: Aliyun CLI >= 3.3.3 required** > > Run `aliyun version` to verify >= 3.3.3. If not installed or version too low, > run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to update, > or see `references/cli-installation-guide.md` for installation instructions. ``` ### Technical Analysis The installation instructions pipe a remotely retrieved script directly into Bash. The payload is neither pinned to a reviewed version nor verified using a cryptographic signature or checksum before execution. Although the URL appears associated with Alibaba Cloud and installing the CLI is relevant to the Skill, this mechanism creates a mutable code-execution channel. The effective code can change after the Skill package has been reviewed. HTTPS protects transport confidentiality and integrity under normal conditions, but it does not protect against compromise of the CDN, publishing account, origin server, or certificate trust chain. Direct remote execution is not the minimum privilege or trust necessary for the declared ALB configuration functionality. A verified package or pinned binary could provide the required CLI without executing an unaudited, mutable script. ### Attack Path 1. An attacker compromises the remote script, its publishing process, the CDN, or another part of the delivery infrastructure. 2. The user or agent follows the documented upgrade instruction. 3. `curl` downloads the attacker-controlled script. 4. The shell pipeline passes the response directly to Bash without inspection or integrity verification. 5. The payload executes with all privileges of the invoking user. 6. If the user runs the command from an elevated shell or the installer invokes privilege elevation, the impact may extend to system-level modification. 7. The payload coul ...[truncated 641 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Mandatory Unpinned Automatic Plugin Installation and Updates

Content
View full analysis
Then **[MUST]** run the following commands before Alibaba Cloud service calls: > > ```bash > aliyun configure set --auto-plugin-install true > aliyun plugin update > aliyun configure ai-mode set-user-agent --user-agent AlibabaCloud-Agent-Skills/alibabacloud-network-alb-http-to-https > aliyun configure ai-mode enable > ``` ``` The same update process is repeated in the workflow at `SKILL.md:115-120` and recommended in `references/cli-installation-guide.md:70-74`. ### Technical Analysis The Skill mandates enabling automatic plugin installation and updating installed plugins immediately before credentialed cloud operations. No exact plugin versions, expected checksums, or signature-verification requirements are specified. Product plugins are executable dependencies used by later ALB and CAS commands. Consequently, a compromised or unexpectedly changed plugin can execute in the same local context as the CLI and may have access to the configured Alibaba Cloud identity. The update operation is relevant to satisfying the Skill’s dependencies, but mandatory updates on every run exceed the minimum necessary behavior. A previously reviewed compatible plugin could be used without introducing a new supply-chain decision into each credentialed invocation. ### Attack Path 1. An attacker compromises a plugin release, registry, publication account, or plugin delivery channel. 2. The user or agent executes the mandatory `aliyun plugin update` command. 3. The altered plugin is installed without a Skill-enforced version or integrity check. 4. A subsequent `aliyun alb` or `aliyun cas` command loads or invokes the plugin. 5. Malicious plugin logic executes in the local user context. 6. The plugin can attempt to access local files, CLI configuration, environment credentials, and permitted cl ...[truncated 578 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:20
Finding

Mutable Latest CLI Binaries Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_cert.sh:64
Finding

TLS Private Key Exposed Through Process Command-Line Arguments

Content
View full analysis
&2 RESULT=$(run_cli "Failed to upload certificate." \ "${ALIYUN_CMD[@]}" cas upload-user-certificate \ --name "$NAME" \ --cert "$CERT_CONTENT" \ --key "$KEY_CONTENT") ``` ### Technical Analysis The script reads the complete private key into a shell variable and then supplies it to the Aliyun CLI through the `--key` command-line argument. Command-line arguments may be visible to process inspection utilities, operating-system auditing, endpoint monitoring, crash collection, or diagnostic tooling. The exact visibility to other users depends on operating-system configuration, but secrets in process arguments should not be treated as confidential. The Bash array-based command construction prevents shell metacharacters in the key from becoming command injection. The confirmed issue is secret exposure through `argv`, not command injection. ### Attack Path 1. The user invokes `upload_cert.sh` with a TLS private-key file. 2. The script reads the private key into `KEY_CONTENT`. 3. The script launches the Aliyun CLI with the full key supplied as an argument. 4. A local process observer, audit service, monitoring agent, or diagnostic collector records the process arguments while the command is running. 5. An attacker with access to that process information or collected telemetry retrieves the private key. 6. If the corresponding certificate remains in use, the attacker may use the key to impersonate the protected service. ### Impact Assessment Exposure grants possession of the uploaded TLS private key. This does not directly grant operating-system or Alibaba Cloud account privileges, but it can permit service impersonation and ma ...[truncated 303 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_test_cert.sh:31
Finding

Predictable Temporary Directory and Incomplete Private-Key Lifecycle Protection

Content
View full analysis
&2; exit 1 ;; esac done if [[ -z "$DOMAIN" ]]; then echo "Error: --domain is required." >&2 exit 1 fi if ! command -v openssl &>/dev/null; then echo "Error: openssl is not installed." >&2 exit 1 fi mkdir -p "$OUT_DIR" CERT_FILE="$OUT_DIR/cert.pem" KEY_FILE="$OUT_DIR/key.pem" echo "Generating self-signed certificate for $DOMAIN ..." >&2 openssl req -x509 -newkey rsa:2048 -nodes \ -keyout "$KEY_FILE" \ -out "$CERT_FILE" \ -days "$DAYS" \ -subj "/CN=$DOMAIN" \ -addext "subjectAltName=DNS:$DOMAIN" \ 2>/dev/null ``` ### Technical Analysis The script writes an unencrypted private key to a predictable shared path, `/tmp/alb-test-certs/key.pem`. It uses `mkdir -p` rather than creating a unique temporary directory atomically, does not explicitly set `umask 077`, and does not verify that the directory and output paths are owned by the current user and are not symbolic links. The script also lacks a cleanup trap, so generated key material remains on disk after generation and upload. The `-nodes` option intentionally creates an unencrypted private key, making filesystem protections and prompt cleanup especially important. Actual file permissions can depend on OpenSSL and the caller’s environment. The script should not rely on environmental defaults for sensitive key material. ### Attack Path 1. An attacker with local access anticipates the documented `/tmp/alb-test-certs` path. 2. The attacker monitors the directory or prepar ...[truncated 1136 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is specifically about enabling and verifying HTTP-to-HTTPS redirects on an Alibaba Cloud ALB, including checking current listener/rule configuration, creating missing HTTP/HTTPS listeners, and adding redirect rules. The supplied code only implements listener creation via alb create-listener with DefaultAction fixed to ForwardGroup. Its own comments explicitly say redirect behavior should be handled by a different script (create_rule.sh). While it does perform related ALB listener setup and prechecks (ALB active state, existing listener on port), it lacks the core redirect functionality and rule inspection described. This is a material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a focused skill for enabling HTTP-to-HTTPS redirects on an Alibaba Cloud ALB, including inspecting current listener/rule setup and creating missing HTTP or HTTPS listeners if needed. The code chunk is narrower in some ways and broader in others: it requires an existing listener ID, does not create listeners at all, and only performs limited inspection/prechecks (get listener attributes and list rules). At the same time, it exposes additional general-purpose rule creation capabilities unrelated to HTTPS enforcement, namely forward-group and fixed-response actions. Those are materially undeclared capabilities, and the omission of listener creation is a significant gap versus the declared purpose. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on end-to-end HTTPS enforcement for an ALB: checking listener/rule state, creating listeners as needed, and adding an HTTP-to-HTTPS redirect rule. The actual script performs a narrower, different action: it creates an empty server group in a specified VPC using the aliyun CLI. Although the comments mention this may be used as a placeholder for HTTP listeners that serve redirect rules, the code itself does not configure any listener or redirect behavior. This is a material mismatch in primary purpose and implemented capabilities, not merely a supporting detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is ALB redirect management on Alibaba Cloud, specifically checking and configuring listeners and redirect rules for HTTPS enforcement. The actual code only creates a local self-signed test certificate with openssl and prints a suggested next step to upload it. That is a different primary purpose and operates on different resources (local filesystem and openssl rather than cloud ALB configuration APIs).

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a remediation/configuration skill for enforcing HTTPS on an ALB, including listener/rule inspection and creation of missing resources. The actual code chunk is limited to a single read-only helper script that fetches one listener's attributes and prints them. While it can surface default redirect actions if already present on that listener, it does not implement the main advertised behaviors: no redirect enforcement, no listener creation, no rule management, and no broader ALB configuration checking. This is a material description-to-behavior mismatch, not merely an incomplete snippet of supporting logic, because the code's primary function is inspection of one listener rather than configuration of HTTP-to-HTTPS redirects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes an active configuration/verification skill for HTTPS enforcement on an ALB. In contrast, this script is a read-only utility for fetching ALB instance attributes (alb get-load-balancer-attribute) and resolving a load balancer name to ID (alb list-load-balancers). It operates on ALB instance metadata such as status, DNS name, VPC, zones, and deletion protection. There is no code related to listeners, forwarding rules, redirect actions, port 80/443 handling, or any create/update operations. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a remediation/configuration skill that can inspect current setup and create missing listeners or redirect rules to enforce HTTP-to-HTTPS. The actual script is read-only: it calls alb list-listeners and formats the response. While it can help inspect whether listeners and default redirect actions exist, it does not perform the main declared actions of configuring HTTPS enforcement or modifying ALB state. Therefore the code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about configuring HTTP-to-HTTPS redirects on existing ALBs, including examining listener/rule setup and making changes to enforce HTTPS. The supplied code only invokes aliyun alb list-load-balancers and formats the returned load balancer inventory. It does not access listener configuration, rule configuration, redirect settings, or perform any create/update operations. While it operates on the general ALB resource domain, its primary purpose is materially different from the declared redirect-configuration behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a remediation/configuration skill for enabling HTTPS enforcement on an ALB, including creating listeners and adding redirect rules. The supplied code chunk is only a read-only inspection utility (list_rules.sh) that calls alb list-rules and prints existing rule details. While listing rules could support checking whether a redirect exists, the code does not inspect listeners, create listeners, or modify ALB configuration in any way. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about enforcing HTTPS by configuring HTTP-to-HTTPS redirects on an ALB, including checking existing listener/rule setup and creating missing listeners or redirect rules. The supplied script does something materially different: it updates the default certificate bound to an existing HTTPS or QUIC listener. It calls get-listener-attribute, checks ListenerProtocol, and uses update-listener-attribute --certificates CertificateId=... to replace the certificate, then polls until the new certificate is observed. There is no logic related to HTTP listeners, port 80/443 redirect behavior, listener creation, or rule creation. This is a clear description-behavior mismatch with a different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about ALB HTTP-to-HTTPS redirect configuration: checking listeners/rules, creating listeners, and adding redirect rules. The supplied code does none of that. Instead, it parses arguments for certificate name and PEM/key file paths, reads those local files, and calls aliyun cas upload-user-certificate to upload a certificate to Certificate Management Service. While a certificate could be a supporting prerequisite for HTTPS listeners, this script’s primary purpose is certificate upload, not redirect enforcement or ALB configuration. Therefore the code materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to execute a remote installation script via curl ... | bash, which is a classic supply-chain and arbitrary code execution risk. If the remote server, CDN, transport path, or hosted script is compromised, the user will execute attacker-controlled code immediately in their shell with their current privileges.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
> **Pre-check: Aliyun CLI >= 3.3.3 required**
>
> Run `aliyun version` to verify >= 3.3.3. If not installed or version too low,
> run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to update,
> or see `references/cli-installation-guide.md` for installation instructions.
>
> Then **[MUST]** run the following commands before Alibaba Cloud service calls:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
bash scripts/create_server_group.sh --region <REGION> --name http-placeholder --vpc-id <VPC_ID>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
bash scripts/create_server_group.sh --region <REGION> --name http-placeholder --vpc-id <VPC_ID>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
bash scripts/create_listener.sh --region <REGION> --lb-id <ALB_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
bash scripts/create_listener.sh --region <REGION> --lb-id <ALB_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
bash scripts/create_listener.sh --region <REGION> --lb-id <ALB_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
bash scripts/create_rule.sh --region <REGION> --listener-id <HTTP_LSN_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
bash scripts/create_rule.sh --region <REGION> --listener-id <HTTP_LSN_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
bash scripts/create_rule.sh --region <REGION> --listener-id <HTTP_LSN_ID> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
bash scripts/create_rule.sh --region <REGION> --listener-id <HTTP_LSN_ID> \

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/ram-policies.md (reported line 21)May include surrounding context.

md
## Notes

- This is a read-write skill and therefore legitimately requires write permissions.
- Do not replace these granular permissions with wildcard permissions such as `alb:*` or `cas:*`.
- If the target ALB and HTTPS certificate already exist, only a subset of the permissions may be exercised in a given run.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script’s actual behavior updates TLS certificates on existing HTTPS/QUIC listeners, which is materially different from the skill’s stated purpose of configuring HTTP-to-HTTPS redirects. In an automation context, this mismatch can cause operators or downstream agents to invoke the script expecting a safe redirect change but instead alter production certificate bindings, creating service disruption, certificate misconfiguration, or unintended security regressions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as enforcing HTTP-to-HTTPS redirects on an existing ALB, but this script adds unrelated certificate-upload capability. That scope expansion is dangerous because it introduces handling of highly sensitive secrets and privileged certificate-management actions that a user would not reasonably expect from a redirect-focused skill, increasing the attack surface and the chance of unintended credential or key exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.