Back to skill

Security audit

alibabacloud-oss-backup-integration-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

This is an advice-only OSS backup diagnosis skill with no cloud changes or credential use, though its online documentation lookup should be clearer.

Install only if you are comfortable with the skill running a local Python diagnostic script and, for official document verification, contacting help.aliyun.com and caching public doc indexes locally. Do not provide credentials; the skill does not need them and should only give configuration advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's declared behavior says diagnosis is zero-cloud-API and configuration-only, but the implementation reportedly performs live network retrieval and centers on doc discovery rather than the described deterministic offline diagnosis. This mismatch is dangerous because operators may approve or route sensitive user cases under false assumptions about what the skill does, enabling unexpected external communication and weakening trust boundaries around data handling and execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly claims constrained, offline-only behavior, but it declares no permissions or allowed-tools scope despite detected file-write and network capabilities. In an agent environment, this creates an ambient-authority problem: the skill may be able to access the network or write files beyond what users and orchestrators expect, increasing the chance of unauthorized data exfiltration, policy bypass, or unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger clause ends with "or any third-party backup tool integration error against OSS," which is much broader than the otherwise specific examples. This lacks clear constraints or exclusion conditions, increasing the risk that unrelated OSS issues get routed to this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The line requires technical tokens to remain in their original language even when the surrounding prose is Chinese, implying a specific output language convention. This is a language policy constraint that is not presented as user-selectable or justified as region-specific output behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/ram-policies.md (reported line 19)May include surrounding context.

md
## Credential handling

Never ask the user for, read, print, or forward any AccessKey, secret, or
STS token. The diagnosis input is limited to: backup tool name/version,
error message text, symptom description, storage class, bucket name and
region — all non-sensitive strings.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s advertised boundary is 'zero cloud API calls' and knowledge-only diagnosis, but it invokes a separate runtime document lookup path based on user-supplied --question input. Because _doc_lookup is external to this file, it may perform network access, file access, or other side effects that violate the declared trust boundary and can expose customer-provided text to unintended destinations. This is primarily an integrity/privacy and security-boundary issue rather than direct code execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module header states the script is a pure embedded-catalog mapper with no network/API behavior, yet the code contains an additional runtime verification stage. Even if that stage is harmless, the mismatch creates a deceptive security contract that can cause operators to approve or run the skill under false assumptions about external dependencies and data handling. In a security-sensitive agent environment, inaccurate boundary documentation is itself risky.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.