Back to skill

Security audit

Alibabacloud Sas Incident Manage

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Alibaba Cloud incident-query skill, but it needs review because broad triggers can lead to live security-data queries using the user's configured cloud credentials.

Review before installing. Use it only with authorized Alibaba Cloud accounts, prefer a least-privilege RAM user or temporary credentials, and require explicit confirmation before any live incident query. Expect it to install/use the Aliyun cloud-siem CLI plugin and local credential profile.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The acceptance criteria explicitly override the expected product scope by instructing use of `cloud-siem` instead of `sas`, creating a product/API mismatch that can cause the agent to operate against a different service than users or the manifest expect. In a security incident-management skill, this is dangerous because it can lead to querying the wrong backend, producing incorrect security conclusions, failed actions, or unintended data access across service boundaries.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad generic phrases such as "安全事件", "事件查询", and "安全态势", which can match normal discussion rather than an explicit request to run this skill. Because the skill is capable of querying real incident data from Alibaba Cloud Security Center, unintended invocation could cause unnecessary transmission of security metadata and disclose sensitive incident information in the session.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The documented default behavior says to run a basic query when no specific filter is mentioned, which lowers the threshold for executing live API calls without confirming user intent. In a security-incident context, even a basic query may reveal sensitive operational data or create unintended access/audit activity if the user was only asking for guidance or documentation.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill describes querying incidents and threat trends but does not clearly warn users that executing the commands sends incident-related parameters and retrieves sensitive security data from Alibaba Cloud APIs. In a SOC/security context, lack of upfront disclosure increases the risk of users invoking the skill without understanding that live environment data will be accessed and potentially surfaced back into the conversation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.