Back to skill

Security audit

Alibabacloud Pts Reporter

Security checks for vulnerabilities and agentic risk

Overview

This read-only PTS report analyzer is mostly coherent, but it needs review because it installs or updates mutable cloud CLI components without verification and always enumerates account PTS scenes.

Install only after reviewing the CLI setup path. Prefer a trusted package manager or verified, pinned Aliyun CLI release, avoid unconditional plugin updates, use a least-privilege RAM role limited to the exact PTS read actions needed, and be aware the skill may list PTS scenes beyond the specific report you asked it to analyze.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
references/cli-installation-guide.md:20
Finding

Unverified Mutable Aliyun CLI Binary Installation

Content
View full analysis
Remediation
View remediation
" ARCHIVE="aliyun-cli-linux-${CLI_VERSION}-amd64.tgz" wget "https:///${ARCHIVE}" wget "https:///${ARCHIVE}.sha256" sha256sum --check "${ARCHIVE}.sha256" tar -xzf "${ARCHIVE}" ``` 5. Where vendor signatures are available, verify the signature against a pinned, documented vendor public key. 6. Inspect archive entries before extraction and reject absolute paths, parent-directory traversal, links, or unexpected files. 7. Prefer an authenticated operating-system package manager with signature verification and version pinning. 8. Avoid replacing commands in a privileged PATH until verification has completed. Prefer a dedicated, least-privileged installation directory when practical. 9. Pin the PTS plugin version if supported and avoid unconditional `aliyun plugin update` during every skill invocation. 10. Correct the statement in `SKILL.md` that promises checksum verification, and add tested verification commands to the installation guide. 11. Document trusted release URLs, expected publisher identities, rollback procedures, and post-installation version validation. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:178
Finding

Unconditional Enumeration of Alibaba Cloud PTS Scenes

Content
View full analysis
**Step 0.1: Environment Discovery (ALWAYS EXECUTE)** > > Before resolving specific report parameters, ALWAYS call the following to discover > the current environment's available resources: > > ```bash > aliyun pts list-pts-scene --region-id --page-number 1 --page-size 20 --read-timeout 60 --connect-timeout 10 > ``` > > This call serves two purposes: > 1. Validates that the CLI credentials work and PTS service is accessible > 2. Provides a list of available scenes for parameter resolution > > If this call succeeds and returns scenes: > - Match the user-provided `SceneId` against the list. > - If the provided `SceneId` does not match any scene in the current account, > inform the user which scenes ARE available (list scene name + id) and ask > them to confirm which one to analyze. ... > This `ListPtsScene` call MUST be issued **regardless of whether the user > already supplied `SceneId` / `PlanId` / `HistoryReportId`** — it is the > canonical environment-discovery probe and is required for evaluation traces. ``` The related permission is granted in `references/ram-policies.md`, lines 12–27: ```json { "Version": "1", "Statement": [ { "Effect": "Allow", "Action": [ "pts:GetPtsReportDetails", "pts:GetPtsSceneRunningData", "pts:GetPtsSceneBaseLine", "pts:GetJMeterReportDetails", "pts:GetPtsScene", "pts:ListPtsScene" ], "Resource": "*" } ] } ``` ### Technical Analysis The workflow requires `ListPtsScene` even when the user has already supplied all identifiers needed to retrieve a specific report. In that case, enumerating up to 20 unrelated scenes does not contribute to resolving the requested resource. The returned scene inventory enters the ...[truncated 2546 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
> **Error Handling & Retry Policy**
>
> - If any CLI command fails, first run `aliyun pts <command> --help` to verify correct syntax
> - Maximum retry per command: **2 attempts**. Do NOT retry indefinitely.
> - If the error is "parameter missing" or "invalid parameter": fix the parameters and retry once
> - If the error persists after 2 retries: report the exact error message to the user and **exit gracefully**
> - Always run `aliyun configure ai-mode disable` before any exit (success or failure)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is advertised as a read-only analyzer for historical PTS reports, but it also instructs fetching live running scene data. That expands data access beyond the stated contract and can expose current operational details or normalize use of broader permissions than users expect from a past-report analysis skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file is far broader than a read-only PTS report analyzer: it covers generic CLI installation, authentication, ECS commands, plugin installation, proxying, custom endpoints, and non-PTS service exploration. Over-scoped operational guidance in a skill increases the attack surface by normalizing capabilities the skill should not need, making privilege expansion and accidental misuse more likely in agent-driven environments.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide says the skill relies on the default credential chain and that credentials should not be configured explicitly, but then immediately documents explicit authentication modes and setup commands. In an agent skill context, this contradiction can push operators or downstream automation toward unnecessary credential handling, increasing the chance of secret sprawl, misconfiguration, or use of over-privileged long-lived credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Recommending --log-level=debug on authenticated cloud API calls without warning about sensitive output can expose request metadata, tokens, profile details, endpoints, or other secrets in terminal logs, CI logs, or agent traces. In automated environments, debug output is often retained centrally, magnifying the blast radius of accidental disclosure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 217)May include surrounding context.

md
### 1. Use RAM Users (Not Root Account)

❌ **Don't**: Use Aliyun root account credentials
✅ **Do**: Create RAM users with specific permissions in the RAM console

### 2. Principle of Least Privilege

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 248)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill claims narrow report-only analysis, yet it mandates scene enumeration and metadata discovery even when the user already supplied required identifiers. This broadens resource discovery across the account and violates least-privilege expectations for a focused report-analysis workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide links users to https://help.aliyun.com/zh/cli/, which hardcodes the Chinese locale in the primary documentation reference. Because no alternative language option or justification is provided, this creates a natural-language locale policy issue under the requirement to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The section encouraging installation of arbitrary Alibaba Cloud product plugins and exploration of non-PTS commands expands user and agent expectations beyond the skill’s stated purpose. While not directly exploitable on its own, it can enable capability creep and create a path for misuse of broader cloud operations under the cover of a read-only analysis skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The references list repeats the locale-specific https://help.aliyun.com/zh/cli/ link, reinforcing a forced language choice. The file does not indicate that the skill is limited to Chinese-speaking users or provide an alternate locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.