Back to skill

Security audit

alibabacloud-sls-dashboard

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Alibaba Cloud SLS dashboard work, but it has a real credential-safety issue when HTTP endpoint overrides are used.

Review carefully before installing. Use HTTPS-only endpoints, avoid http:// endpoint overrides, and use a least-privilege Alibaba Cloud profile. Treat publish, delete, and subscription create/update/delete as real cloud changes; confirm the target project, dashboard, recipients, and schedule before running commands with --execute.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/common.py:48
Finding

Cloud Credentials Can Be Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/lib/common.py:48-63, with the credential-bearing request at scripts/lib/metric_api.py:48-65
Vulnerability Type: Plaintext transmission of cloud credentials
Risk Level: High

Complete Code Snippet

scripts/lib/common.py:48-63:

python
def sls_endpoint(endpoint, region, project):
    """Return scheme and service authority for SDK/HTTP transports."""
    value = endpoint if endpoint is not None else f"{region}.log.aliyuncs.com"
    if not isinstance(value, str) or not value.strip() or any(c.isspace() for c in value):
        raise SkillError("Endpoint must be a SLS service host or HTTP(S) base URL")
    try:
        parsed = urlsplit(value if "://" in value else "https://" + value)
        port = parsed.port
    except ValueError as exc:
        raise SkillError("Invalid SLS endpoint") from exc
    if (parsed.scheme not in {"http", "https"} or not parsed.hostname or
            parsed.username is not None or parsed.password is not None or
            parsed.path not in {"", "/"} or parsed.query or parsed.fragment):
        raise SkillError("Endpoint must be a SLS service host or HTTP(S) base URL without credentials or API path")
    hostname = parsed.hostname

scripts/lib/metric_api.py:48-65:

python
password = secret + ("$" + token if token else "")
return base64.b64encode((key + ":" + password).encode()).decode()

def request(self, source, operation, params):
    if source["type"] != "metricstore_storeview":
        raise SkillError("This transport is for SLS metric StoreViews")
    if operation not in {"query", "query_range", "series", "label/__name__/values"}:
        raise SkillError("Unsupported metric read operation")
    project, region, name = source["project"], source["region"], source["name"]
    if not all(re.fullmatch(r"[a-z0-9][a-z0-9-]*", value) for value in (project, region)):
        raise SkillError(
...[truncated 2876 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change sls_endpoint() to accept only https for authenticated cloud operations:

    python
    if parsed.scheme != "https":
        raise SkillError("Endpoint must use HTTPS")
    
  2. Update references/datasources/api.md and all CLI help text to state that endpoint overrides must be HTTPS.

  3. If plaintext HTTP is required for isolated testing, place it behind an explicit test-only option that is disabled by default and cannot load real credential profiles.

  4. Add automated tests confirming that http:// endpoints are rejected before _credentials() is called or any request is sent.

  5. Consider restricting production endpoints to expected SLS service domains or an explicit administrator-controlled allowlist where deployment requirements permit it.

  6. Rotate any credentials that may previously have been used with plaintext HTTP endpoints.

Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (88)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes scheduled report subscription/job management, which is operationally different from dashboard visualization editing and may involve creating, updating, or deleting job resources. That broader operational surface can produce side effects and access patterns not implied by a dashboard-design description, leading to over-trust and under-scoped approvals.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes scheduled report subscription/job management, which is operationally different from dashboard visualization editing and may involve creating, updating, or deleting job resources. That broader operational surface can produce side effects and access patterns not implied by a dashboard-design description, leading to over-trust and under-scoped approvals.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes scheduled report subscription/job management, which is operationally different from dashboard visualization editing and may involve creating, updating, or deleting job resources. That broader operational surface can produce side effects and access patterns not implied by a dashboard-design description, leading to over-trust and under-scoped approvals.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill includes scheduled report subscription/job management, which is operationally different from dashboard visualization editing and may involve creating, updating, or deleting job resources. That broader operational surface can produce side effects and access patterns not implied by a dashboard-design description, leading to over-trust and under-scoped approvals.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill includes scheduled report subscription/job management, which is operationally different from dashboard visualization editing and may involve creating, updating, or deleting job resources. That broader operational surface can produce side effects and access patterns not implied by a dashboard-design description, leading to over-trust and under-scoped approvals.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
- Prefer a [Plan](references/model/plan.md) for new content. Complete Dashboard JSON

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/integrations/subscriptions.md (reported line 16)May include surrounding context.

md
| List the dashboard's subscriptions | ListJobs: GET /jobs |
| Create | CreateJob: POST /jobs with the complete Report body |
| Update | UpdateJob: PUT /jobs/{jobName} with the complete Report body |
| Delete | DeleteJob: DELETE /jobs/{jobName} |

ListJobs uses these exact filters:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill instructs the agent to read files, inspect environment state, invoke Python scripts, use shell commands, and perform cloud/network operations, but it does not declare any explicit tool scope or permission boundaries. That makes the effective authority broader than the metadata suggests and increases the risk of unintended command execution, file access, or credentialed cloud actions if the skill is invoked in a permissive runtime.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 16)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 20)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 21)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 22)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 23)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 24)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 25)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 26)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 27)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 28)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 29)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 30)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 31)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 32)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 33)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 34)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/charts/droplistpro.md (reported line 35)May include surrounding context.

md
| `basicOptions.showTime` | boolean | No | false | Show the query time in the header. |
| `fixedTop` | boolean | No | false | Place the control in the dashboard's top variable area. |
| `fixedTopOrder` | number | No | — | Order among top-fixed controls. |
| `showDropListChart` | boolean | No | — | Show the control; hiding it does not remove its saved configuration. |
| `bindQuery` | boolean | No | false | Query dynamic candidates for filter or token mode. |
| `search.chartQueries` | object[] | For dynamic or adhoc | None | Candidate query for filter/token; metric resource for adhoc. |
| `search.isInheritFilter` | boolean | No | — | Let a log-backed candidate query inherit other field filters, excluding its own. |

Static analysis

No suspicious patterns detected.