Back to skill

Security audit

Alibabacloud Nginx Ingress To Api Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned for offline nginx-to-APIG migration, but its generated gateway-plugin guidance includes unsafe authorization and deployment patterns that need careful review before use.

Review generated WasmPlugin code before deployment, especially any authentication or authorization plugin. Change external-auth examples to fail closed on dispatch errors, pin dependencies and image digests or reviewed versions, avoid persistent global Go proxy changes unless intentional, preview and namespace-scope kubectl delete commands, and treat request bodies, Authorization headers, mirrored traffic, and log attributes as sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/wasm-plugin-sdk.md:216
Finding

External Authorization Plugin Fails Open When Call Dispatch Fails

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/wasm-plugin-sdk.md:18
Finding

Mutable and Incompletely Pinned Go Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
go get github.com/higress-group/wasm-go@ go get github.com/tidwall/gjson@v1.18.0 ``` 2. Ship a complete reviewed `go.mod` and `go.sum` template with the scaffold rather than instructing users to resolve dependencies dynamically. 3. Run builds with `-mod=readonly` after dependency lock files have been generated and reviewed. 4. Verify module checksums through an approved checksum database or internal artifact repository. 5. Avoid persistent global configuration with `go env -w`. Scope the proxy to the individual command or build script: ```bash GOPROXY=https://,direct go mod download ``` 6. Document the trust and ownership of the selected proxy and provide an option to use an organization-controlled module mirror. 7. Generate and retain an SBOM for each plugin image, and scan dependencies before publishing the OCI artifact. 8. Use immutable OCI image digests in production deployment annotations where supported. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyze-ingress-offline.sh:143
Finding

Untrusted Annotation Values Can Inject Terminal Control Sequences

Content
View full analysis
&2 fi KEPT_ANNOS=$(echo "$KEPT_ANNOS" | jq --arg n "$ANNO_NAME" --arg v "$VALUE" '. + [{"name": $n, "value": $v}]') elif annotation_in_set "$ANNO_NAME" "${IGNORE_ANNOTATIONS[@]}"; then HAS_IGNORABLE=true if [[ "$JSON_ONLY" == false ]]; then echo -e " ${YELLOW}○ Ignore: $ANNO_NAME${NC} = $VALUE (not needed in Envoy)" >&2 fi IGNORED_ANNOS=$(echo "$IGNORED_ANNOS" | jq --arg n "$ANNO_NAME" --arg v "$VALUE" '. + [{"name": $n, "value": $v}]') else HAS_UNSUPPORTED=true if [[ "$JSON_ONLY" == false ]]; then echo -e " ${RED}✗ Unsupported: $ANNO_NAME${NC} = $VALUE (needs WasmPlugin)" >&2 fi UNSUPPORTED_ANNOS=$(echo "$UNSUPPORTED_ANNOS" | jq --arg n "$ANNO_NAME" --arg v "$VALUE" '. + [{"name": $n, "value": $v}]') fi fi done < <(echo "$ingress" | jq -r '.metadata.annotations // {} | keys[]') ``` ### Technical Analysis `VALUE` is extracted directly from user-supplied YAML. It is subsequently included in an `echo -e` argument. The `-e` option instructs `echo` to interpret backslash escape sequences after shell variable expansion. A crafted annotation value containing sequences such as `\e`, `\033`, carriage returns, or other control characters ...[truncated 1534 chars]
Remediation
View remediation
&2 ``` 2. Ensure `%s`, not `%b`, is used for all annotation names and values so their escape sequences remain literal. 3. Remove or visibly encode terminal control characters before displaying values. For example, convert characters below ASCII 0x20, except safe whitespace, into escaped representations. 4. Consider emitting the human-readable report through `jq @json` or a dedicated escaping function when values may contain newlines. 5. Keep ANSI color handling limited to constant, application-controlled strings. 6. Add regression tests using annotation values containing `\e`, `\033`, `\r`, embedded newlines, OSC sequences, and other control characters. 7. Recommend `--json-only` for automated processing, while still ensuring that downstream consumers safely render JSON string values. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code aligns with part of the description: it performs offline analysis of nginx Ingress YAML without cluster access and classifies annotations for APIG migration compatibility. However, the declared purpose is broader and promises multiple migration capabilities that are not present in this code chunk. The actual code only analyzes one YAML file and outputs classification results; it does not generate migrated Ingress YAML, map resources to Higress-native constructs, select built-in plugins in any concrete way, develop WasmPlugins, or produce a substantive migration report/deployment guide. This is a description-behavior mismatch because significant declared capabilities are absent from the supplied code.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
6. For custom WasmPlugin, use `github.com/higress-group/wasm-go/pkg/wrapper` SDK exclusively
7. Track annotation value changes (e.g., `ewma` → `round_robin`) explicitly in the report
8. For `server-snippet`/`configuration-snippet`, enumerate every directive and verify 1:1 conversion completeness
9. Never execute cluster write operations (`kubectl apply`, `docker push`, etc.) — only output instructions for the user

## Reference Links

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/builtin-plugins.md (reported line 15)May include surrounding context.

md
| `basic-auth` | HTTP Basic Auth (RFC 7617) | `auth_basic` directive | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/basic-auth-plug-ins) |
| `hmac-auth` | HMAC signature-based authentication | Signature validation scripts | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/hmac-auth-plug-ins) |
| `jwt-auth` | JWT validation from URL params, headers, or cookies; supports per-caller credentials | JWT Lua scripts, `auth_request` for JWT | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/jwt-auth-plug-ins) |
| `oauth` | OAuth 2.0 Access Token issuance based on JWT (RFC 9068) | OAuth Lua scripts | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/oauth-plugin) |
| `jwt-logout` | JWT logout & unique-login control via Redis; supports session kick-off across devices | Custom session invalidation logic | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/jwt-logout-plug-ins) |

## Traffic Control

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill states it operates offline and does not execute tools, yet it contains instructions referencing file-path and directory handling plus shell-based verification/tool checks, while declaring no explicit tool scope. That mismatch can lead an agent runtime to grant broader-than-necessary file_read or shell capabilities, increasing the risk of unintended local file access or command execution if the skill is invoked on untrusted input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction says all output should use Chinese, which imposes a language choice regardless of the user's preference. This is a natural-language policy issue because the file does not offer an opt-in or alternative language selection.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
See `references/deployment-guide-template.md` for the guide template.

> **Scope boundary**: This skill generates all artifacts and instructions. It does NOT execute `kubectl apply`, `docker push`, or any cluster/registry write operations. Those are left to the user.
> **No confirmation needed**: Every item above is always generated. Never ask "是否需要生成迁移文件/检查清单/部署指南?"

## Success Verification Method

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes user-facing migration guidance entirely in Chinese in the acceptance examples, with no indication that the skill supports language selection or that Chinese is a justified locale constraint. That can violate language/locale policy because it implicitly requires a specific language for user instructions without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance recommends replacing unsupported annotations with built-in or custom WasmPlugins, including external auth callouts, header/body manipulation, mirroring, and WAF behavior, but it does not warn that these extensions can change trust boundaries and expose sensitive traffic or credentials. In this skill context, users may rely on the migration output as safe-by-default, so missing cautions can lead to deployment of plugins that exfiltrate request data, mishandle authentication, or introduce unsafe custom code paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

proxy-request-buffering is listed as unsupported with an implied WasmPlugin replacement path, but the surrounding text says it can usually be safely dropped. That contradiction can lead the agent to over-prescribe custom plugins for a setting that may not need one, or worse, to drop buffering semantics without flagging edge cases where backends require buffered requests, causing request handling errors or data-path regressions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file labels denylist-source-range as unsupported, yet the note immediately states APIG officially supports the equivalent control via higress.io/blacklist-source-range. A migration agent following the unsupported classification may strip an active blacklist or replace it incorrectly with a plugin instead of the native security control, weakening access restrictions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document gives a blanket rule that every unsupported annotation must be replaced with a WasmPlugin, but later carves out service-upstream as an exception that should simply be stripped. This inconsistency can cause the migration agent to generate unnecessary plugin references or conflicting migration outcomes, increasing the chance of incorrect traffic behavior and avoidable custom extension deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rollback section instructs users to run kubectl delete ingress -l migration.higress.io/source=nginx, which can delete live ingress resources across the selected label set without clearly warning that this is a destructive production action. In a migration skill, users may copy-paste rollback commands under time pressure, so insufficient scoping, confirmation guidance, and safety warnings increase the chance of unintended service disruption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file instructs users to use a region-specific Alibaba Cloud registry and later tells them to check the Alibaba Cloud APIG console, effectively steering operation toward a specific platform/region. The guidance does not offer an opt-in or alternative path, and the locale/platform constraint is not explicitly justified as mandatory beyond a brief implementation note.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes examples that explicitly mention calling external services and routing request bodies upstream, which can transmit request data off-process or off-box. The surrounding documentation does not warn users about privacy or data-handling implications of sending request/response content to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation demonstrates attaching attributes such as user identifiers to access logs and trace spans, which can affect privacy and data retention. There is no accompanying warning advising users to avoid logging sensitive or regulated data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes an example that reads the incoming authorization header and forwards it to another service via config.client.Get(...). Although the document has a general production safety notice, it does not explicitly warn readers that the pattern transmits potentially sensitive credentials or request-derived data to external services, which is the type of disclosure SQP-2 expects in markdown guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file points exclusively to Chinese-language official documentation via a /zh/ URL and does not offer any language choice or note that the content is region/language-specific. This creates a natural-language locale constraint that may not suit all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language policy requires avoiding forced language or locale unless users are given a choice or the constraint is clearly justified. This template presents all operational guidance solely in Chinese and does not indicate that the language is optional or region-specific by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural language entirely in Chinese, with no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script immediately creates a plugin directory and writes several files into it, later also marking generated scripts as executable. While the script prints what it is generating, it does not clearly warn up front that running it will modify the filesystem and create executable helper scripts in the chosen location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.