Back to skill

Security audit

Alibabacloud Pai Workspace Manage

Security checks for vulnerabilities and agentic risk

Overview

The skill is for Alibaba Cloud PAI workspace management, but it needs Review because its setup and examples create unnecessary local, credential, and cloud-account risk.

Install only after reviewing the setup steps. Prefer a package manager or pinned, verified Aliyun CLI release; avoid curl-to-bash, global plugin auto-install/update, and command-line credential secrets. Use least-privilege RAM credentials, confirm every workspace-changing action, and treat deletion instructions as outside normal create/query/list use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:23
Finding

Unverified Remote Installation Script Executed Directly by Bash

Content
View full analysis
Run `aliyun version` to verify >= 3.3.3. If not installed or version too low, > run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to install/update, ``` ### Technical Analysis The installation command sends a mutable HTTPS response directly to Bash. There is no explicit version pinning, checksum validation, signature verification, local inspection step, or approval of the downloaded content. Although the hostname appears associated with Alibaba Cloud, its presence alone does not establish the integrity of every future response. The effective code executed by the Skill can change after the Skill itself has been reviewed. Compromise of the remote hosting infrastructure, CDN distribution path, release process, or applicable TLS trust could therefore turn this command into an arbitrary code-execution channel. Direct remote script execution is not necessary for the declared PAI workspace-management functionality. The project already documents package-manager and separately downloaded binary alternatives. ### Attack Path 1. An attacker compromises or gains control over the remote script, its distribution infrastructure, or an upstream release process. 2. A user or Agent follows the mandatory-looking installation instruction. 3. `curl` downloads the attacker-controlled response. 4. The pipe passes the response directly to Bash without any integrity check or review. 5. The payload executes with the current user's privileges and can access the user's files, environment, CLI configuration, and available cloud credentials. ### Impact Assessment Successful exploitation provides arbitrary local command execution with the privileges of the user running the installation. If run from a credentialed automation environment, the payload may also gain access to Ali ...[truncated 261 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:26
Finding

Mandatory Automatic Installation and Unbounded Updating of CLI Plugins

Content
View full analysis
Then [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > Then [MUST] run `aliyun plugin update` to ensure that any existing plugins on your local machine are always up-to-date. ``` ### Technical Analysis The Skill requires users to enable automatic plugin installation and then update every existing local plugin. Neither operation pins the required plugin to an audited version. Updating all plugins also exceeds the scope of the declared functionality because the Skill only needs the PAI AIWorkSpace functionality, not modifications to unrelated Alibaba Cloud plugins. Plugins may contain executable behavior and run in the context of an authenticated CLI process. Consequently, a malicious or compromised plugin release could execute with access to the user's cloud profile and local environment. The mandatory global update also makes the Skill's behavior non-reproducible because components may change after review. ### Attack Path 1. An attacker compromises a plugin publication account, plugin repository, or upstream build process. 2. A malicious plugin version is published. 3. The Skill enables automatic installation or invokes the unbounded plugin update. 4. The CLI retrieves the compromised component without a version pin or independent integrity policy. 5. The plugin executes during a later CLI operation in the authenticated user's context. ### Impact Assessment A compromised plugin could execute local code, read files available to the user, inspect Alibaba Cloud configuration, and submit cloud API requests within the permissions of the active profile. Updating unrelated plugins can also alter or break tools outside this Skill's declared workspace-management scope. ]]>
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:39
Finding

Unsigned Mutable “Latest” Binary Installed into a System-Wide Executable Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/cli-installation-guide.md:103
Finding

Cloud Credentials Recommended in Command-Line Arguments

Content
View full analysis
\ --access-key-secret \ --region cn-hangzhou ``` The guide then states: ```text All `aliyun configure` commands support non-interactive flags, which is the recommended approach — it works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts. ``` It also provides equivalent examples for long-lived access keys, STS tokens, and role-assumption configurations. ### Technical Analysis Supplying access keys, secrets, and tokens as command-line arguments can expose them through shell history, process inspection, terminal capture, CI/CD logs, debugging output, and Agent execution transcripts. Recommending this method for scripts and Agent-driven automation materially increases the likelihood that credential-bearing commands will be retained in logs. This guidance also conflicts with `SKILL.md:45-47`, which says never to request credentials directly and never to use `aliyun configure set` with literal credential values. ### Attack Path 1. A user follows the guide and substitutes real credentials into the command. 2. The shell records the command in history, an automation platform logs it, or another local process observes its arguments. 3. An unauthorized party obtains the access key, secret, or STS token. 4. The party authenticates to Alibaba Cloud using the exposed credential. 5. The party performs operations permitted by the associated RAM identity until the credential expires or is revoked. ### Impact Assessment The impact equals the permissions assigned to the compromised credential. At ...[truncated 313 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/related-commands.md:28
Finding

Shell Command Injection Through Insufficiently Escaped Workspace Metadata

Content
View full analysis
\ --workspace-name \ --description "" \ --env-types prod \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-workspace-manage ``` ```bash aliyun aiworkspace create-workspace \ --region \ --workspace-name \ --description "" \ --env-types dev prod \ --display-name "" \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-workspace-manage ``` The documented validation permits arbitrary display-name content and only limits the description's length: ```text | `--description` | Max 80 characters, wrap with quotes if containing special characters | | `--display-name` | Optional, no strict format restrictions | ``` ### Technical Analysis Double-quoting a placeholder is not sufficient to make arbitrary text safe for shell interpolation. Within double quotes, command substitutions such as `$(...)` and backticks remain active. Embedded quotes can also terminate the intended argument and introduce operators or additional arguments. The Skill validates workspace names strictly but does not define equivalent shell-safe handling for descriptions or display names. If an Agent builds a command string from the templates and executes it through a shell, malicious metadata can become executable syntax. ### Attack Path 1. An attacker supplies a description or display name containing shell syntax, such as command substitution or an embedded quote followed by shell operators. 2. The value passes the documented validation because the description is within 80 characters or the display name has no strict restrictions. 3. The Agent substitutes the v ...[truncated 529 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/related-commands.md:215
Finding

Sensitive List-Workspace Templates Omit the Required Masking Pipeline

Content
View full analysis
\ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-workspace-manage ``` ```bash aliyun aiworkspace list-workspaces \ --region \ --workspace-name \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-workspace-manage ``` ```bash aliyun aiworkspace list-workspaces \ --region \ --fields Id \ --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-workspace-manage ``` ### Technical Analysis Elsewhere, the Skill explicitly says that every `list-workspaces` response includes creator and administrator account information and that the execution framework records command stdout. It therefore requires a single pipeline that masks the response before output reaches the execution log. However, multiple command blocks are complete, directly executable standalone commands without the masking pipeline. The surrounding prose does not technically enforce masking and an Agent may copy one of these templates verbatim. This creates an internal security contradiction: the policy requires filtering, while the operational examples demonstrate unsafe execution. ### Attack Path 1. An Agent selects one of the standalone list templates. 2. The CLI returns raw workspace objects containing creator or administrator identifiers. 3. The execution framework captures raw stdout in its transcript or execution log. 4. Users, processes, or support personnel with access to those records can retrieve t ...[truncated 456 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (24)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Piping a remote script directly into bash executes unverified code from the network with the user's privileges. In a skill context, this is especially dangerous because it normalizes arbitrary remote code execution during setup and could compromise the host if the distribution channel or content is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
> **Pre-check: Aliyun CLI >= 3.3.3 required**
> Run `aliyun version` to verify >= 3.3.3. If not installed or version too low,
> run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to install/update,
> or see `references/cli-installation-guide.md` for installation instructions.
> Then [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation.
> Then [MUST] run `aliyun plugin update` to ensure that any existing plugins on your local machine are always up-to-date.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
> See `references/related-commands.md` for all CLI command templates and parameter details.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
> See `references/related-commands.md` for all CLI command templates and parameter details.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
> See `references/related-commands.md` for all CLI command templates and parameter details.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

md
> See `references/related-commands.md` for all CLI command templates and parameter details.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The documented DELETE endpoint introduces a destructive API action outside the skill's declared scope and could be misused with attacker-controlled workspace identifiers. In context, this is more dangerous because the skill otherwise appears focused on non-destructive workspace management, so users may not expect deletion guidance to be present.

Content

Scanner excerpt · SKILL.md (reported line 285)May include surrounding context.

md
>
> **Note**: Workspace deletion **cannot be performed directly via CLI** (the `aiworkspace` plugin does not currently support `delete-workspace`). Use the following methods:
> 1. **Console deletion**: Log in to [PAI Console](https://pai.console.aliyun.com/) -> Workspace List -> Select workspace -> Delete
> 2. **API call**: Use the `DELETE /api/v1/workspaces/{WorkspaceId}` endpoint (via SDK or direct HTTP call)

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest-style description lists generic triggers such as "create workspace", "get workspace", and especially "PAI workspace" without clear scope boundaries or exclusion conditions. In a markdown/manifest context, these phrases are broad enough to match ordinary user requests and may cause unintended invocation of this specific Alibaba Cloud skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents deletion through a direct API call even though deletion is outside the declared create/query/list scope. This expands the operational capability into destructive actions and could lead an agent or user to perform irreversible deletion under the guise of a non-destructive management skill.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 91)May include surrounding context.

INCORRECT — Skip activation check and execute operations directly

text
# Prohibited: Creating/querying workspaces without checking PAI activation status
User: "Create a workspace in cn-shanghai"
aliyun aiworkspace create-workspace --region cn-shanghai ...
# Must call list-products to check if PAI is activated first

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 183)May include surrounding context.

INCORRECT — Skip activation check and execute operations directly

text
# Prohibited: Creating/querying workspaces without checking PAI activation status
User: "Create a workspace in cn-shanghai"
aliyun aiworkspace create-workspace --region cn-shanghai ...
# Must call list-products to check if PAI is activated first

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 231)May include surrounding context.

INCORRECT — Skip activation check and execute operations directly

text
# Prohibited: Creating/querying workspaces without checking PAI activation status
User: "Create a workspace in cn-shanghai"
aliyun aiworkspace create-workspace --region cn-shanghai ...
# Must call list-products to check if PAI is activated first

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide repeatedly shows access keys and secrets passed directly on the command line and stored in environment variables without warning that these channels can leak via shell history, process listings, terminal scrollback, CI job logs, and support screenshots. In an agent/automation skill, this is more dangerous because users may copy-paste examples verbatim into shared runners or managed environments where secrets are more broadly observable.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 118)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Recommending authenticated API calls with --log-level=debug without any caution can expose sensitive request details, credential material, signed headers, or other internal diagnostics in console output and logs. In agent-driven workflows, debug output is often captured centrally, which increases the chance of credential or token disclosure beyond the local machine.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 404)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented requirement to call list-products adds a capability outside the declared workspace-management scope by inspecting product activation and purchase state. Even if intended as a prerequisite check, it expands the skill's authority and data access surface, enabling collection or disclosure of commercial/account entitlement information that users may not expect from a create/query/list workspace skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Including list-products, PurchaseUrl, and HasPermissionToPurchase exposes account-level purchasing and entitlement metadata unrelated to basic workspace management. This can leak sensitive business context about subscription state and purchasing authority, and may normalize broader-than-necessary access under a narrowly described skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest says this skill is for creating, querying, and listing PAI workspaces. In the RAM permission failure flow, the documentation adds a capability to invoke a separate ram-permission-diagnose skill to guide permission remediation, which is not part of direct workspace management functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes workspace creation, query, and listing. The core workflow requires calling list-products to inspect whether PAI is activated in a region and then guiding the user through activation or purchase-permission outcomes, which is adjacent account/product-state management rather than workspace management itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The instructions hard-code trigger keywords in Chinese and English for deciding when to use --verbose true, but do not indicate that language handling is configurable or user-selected. This is a natural-language policy concern because the skill embeds locale-specific behavior without an explicit opt-in or broader language-choice statement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.