Back to skill

Security audit

Alibabacloud Solution Deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill automates real Alibaba Cloud infrastructure changes and contains review-worthy risks, including a shell command injection flaw and weak handling of secrets, downloads, and remote diagnostics.

Install only if you are comfortable giving the skill Alibaba Cloud credentials capable of creating, changing, and destroying resources. Use a narrowly scoped RAM user or temporary credentials, review plans and costs before every apply or destroy, avoid putting passwords or tokens directly in Terraform files or CLI commands, and treat the included runtime script as needing a security fix before use because its state-id handling can allow command injection.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
<state_id>`, or - `terraform_runtime_online.sh apply <file> --state-id <state_id>`. 2. The script appends the value to `aliyun_cmd` without shell-safe quoting. 3. `eval "$aliyun_cmd"` reparses the attacker-controlled shell syntax. 4. The injected command executes locally with the same operating-system privileges and environment as the Skill process. 5. The injected process may read local Aliyun credentials, modify files, invoke network tools, or execute further cloud commands. ### Impact Assessment Suc ...[truncated 699 chars]:164
Finding

Shell Command Injection Through Unquoted State IDs and eval

Content
View full analysis
&2 [[ -n "$state_id" ]] && echo "Using existing state: $state_id" >&2 token="$(uuidgen)" aliyun_cmd="aliyun iacservice execute-terraform-plan --endpoint $ENDPOINT --client-token $token --code \"\$code\"" [[ -n "$state_id" ]] && aliyun_cmd="$aliyun_cmd --state-id $state_id" response=$(eval "$aliyun_cmd" 2>&1) || { echo "$(_red)Error: execute-terraform-plan failed$(_reset)" >&2; echo "$response" >&2; exit 1; } ``` The apply path repeats the same construction pattern: ```bash local token aliyun_cmd response new_state_id local max_retries=6 retry_delay=10 retry=0 token="$(uuidgen)" _build_cmd() { local cmd="aliyun iacservice execute-terraform-apply --endpoint $ENDPOINT --client-token $token" [[ -n "$code" ]] && cmd="$cmd --code \"\$code\"" [[ -n "$state_id" ]] && cmd="$cmd --state-id $state_id" echo "$cmd" } aliyun_cmd=$(_build_cmd) while true; do response=$(eval "$aliyun_cmd" 2>&1) && break ``` ### Technical Analysis The script constructs a shell command as a string, appends the caller-supplied `state_id` without quoting or format validation, and executes the result with `eval`. `eval` causes shell syntax contained in `state_id` to be parsed a second time. Consequently, shell metacharacters such as command separators, substitutions, or redirections can alter the intended command and introduce arbitrary local commands. Although legitimate state IDs originate from Alibaba Cloud, the script also accepts state IDs directly from command-line arguments. The code does not establish that the value came from a trusted service response. ### Attack Path ...[truncated 1200 chars]
Remediation
View remediation
&1) || { echo "$(_red)Error: execute-terraform-plan failed$(_reset)" >&2 echo "$response" >&2 exit 1 } ``` 3. Apply the same array-based construction to `execute-terraform-apply`. 4. Validate state IDs against the exact format documented by IaCService before using them. 5. Reject values containing whitespace or shell metacharacters if the service format does not require them. 6. Add regression tests using state IDs containing semicolons, substitutions, quotes, spaces, and redirections, verifying that none can cause a second command to run. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/diagnose_cli_command.py:52
Finding

Unredacted Commands and Error Messages Sent to a Remote Diagnosis Service

Content
View full analysis
dict: client = create_client() params = open_api_models.Params( action='DiagnoseCLI', version='2024-11-30', protocol='HTTPS', method='POST', auth_type='AK', style='ROA', pathname='/diagnoseCLI', req_body_type='json', body_type='json' ) body = {'command': command, 'error': error} runtime = util_models.RuntimeOptions(read_timeout=60000) request = open_api_models.OpenApiRequest(body=body) return client.call_api(params, request, runtime) ``` The Skill explicitly instructs the Agent to provide the complete values: ```bash python3 {{SKILL_PATH}}/scripts/diagnose_cli_command.py '' '' ``` ### Technical Analysis The script sends the full failed command and complete error message to the authenticated remote endpoint `openapi-mcp.cn-hangzhou.aliyuncs.com`. Cloud deployment commands and error output may contain: - Password parameters. - API keys or security tokens. - Connection strings. - Signed URLs. - Authorization headers. - Usernames, account identifiers, endpoints, or internal resource names. - Service responses that echo sensitive request parameters. The script defines `sanitize_response()`, but that function only sanitizes data after the remote service has returned it. It does not redact the outbound `command` or `error` fields before transmission. HTTPS protects the data in transit but does not minimize what the receiving service obtains. The diagnosis functionality is legitimate, but transmitting complete raw inputs exceeds the minimum disclosure necessary when sensitive values can be replaced with placeholders. ...[truncated 1233 chars]
Remediation
View remediation
` so diagnostic context remains usable. 4. Detect known Alibaba Cloud key and token formats even when they are not associated with a recognized flag. 5. Avoid sending the full command by default. Prefer the API action, sanitized parameters, error code, and sanitized message. 6. Require explicit user approval before sending diagnostic content when reliable redaction is not possible. 7. Document the destination endpoint and the exact data categories transmitted. 8. Add tests demonstrating that secrets present in command-line arguments and error text never appear in the serialized outbound request. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:113
Finding

Plaintext Terraform Secrets Are Written Locally and Submitted to Remote IaCService

Content
View full analysis
" { source = "alibabacloud-automation//alicloud" version = "~> 1.0" # Parameters adjusted per user confirmation } ``` ```bash SKILL_DIR="{{SKILL_PATH}}" TF="${SKILL_DIR}/scripts/terraform_runtime_online.sh" STATE_ID=$($TF apply main.tf | grep '^STATE_ID=' | cut -d= -f2) echo "STATE_ID=$STATE_ID" >> terraform_state_ids.env ``` The runtime reads the entire file and submits its contents: ```bash _read_input() { local input="$1" if [[ -f "$input" ]]; then cat "$input" else printf '%s' "$input" fi } ``` ```bash code=$(_read_input "$input") response=$(aliyun iacservice validate-module \ --endpoint "$ENDPOINT" \ --client-token "$token" \ --source Upload \ --code "$code" 2>&1) ``` ### Technical Analysis The workflow allows user-provided passwords and API keys to be embedded directly in Terraform configuration. The entire HCL document is then: 1. Stored in a local file such as `main.tf`. 2. Passed to the Aliyun CLI as a command-line argument. 3. Submitted to the remote IaCService endpoint. 4. Potentially represented in Terraform state, plan output, execution logs, or error messages. The Skill does state that it will not generate secrets itself, but this does not secure secrets supplied by the user. There is no mandatory use of Terraform ...[truncated 1663 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/aliyun-cli-installation-guide.md:15
Finding

Mutable Executable Downloads and Automatic Plugin Installation Without Integrity Verification

Content
View full analysis
Remediation
View remediation
aliyun-cli-linux-amd64.tgz" | sha256sum -c - ``` 3. Verify release signatures where the vendor provides a signing mechanism. 4. Prefer trusted package-manager installations that validate package metadata and provenance. 5. Download to a temporary directory and inspect the archive layout before extraction. 6. Avoid moving binaries into privileged locations until integrity verification succeeds. 7. Do not enable automatic plugin installation globally by default. 8. Ask for explicit consent before installing each required plugin, and pin or record its version. 9. Maintain an allowlist of required plugins and their expected hashes or signatures. 10. Document how users can disable automatic installation after deployment. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill explicitly preserves Terraform STATE_ID for future update or destroy operations and references low-level runtime tooling capable of destroying infrastructure, while the skill description frames the capability as deployment-focused. Undisclosed destructive lifecycle control materially increases risk because users may authorize the skill expecting provisioning assistance, not persistent control over existing resources or deletion workflows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to write files such as main.tf and terraform_state_ids.env, but the manifest does not declare any tool scope or permission boundary for file-writing behavior. Missing explicit scope increases the chance of unintended or overbroad filesystem modification and makes it harder to enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is broad enough to activate on many generic mentions of Alibaba Cloud solutions, without clear exclusions or safety gates. In a cloud-modifying skill, overbroad triggering raises the risk of the agent entering a deployment workflow unexpectedly and guiding or initiating costly, privileged actions in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill strongly emphasizes automation and CLI-first execution but does not present an upfront warning that it may create, modify, and potentially later destroy billable cloud resources. This omission can lead users to engage the skill without appreciating cost, side effects, or the sensitivity of credentialed cloud operations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 30)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 45)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 58)May include surrounding context.

md
tar -xzf aliyun-cli-macosx-latest-amd64.tgz

# Move to PATH
sudo mv aliyun /usr/local/bin/

# Verify
aliyun version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 71)May include surrounding context.

Extract and install

tar -xzf aliyun-cli-linux-latest-arm64.tgz sudo mv aliyun /usr/local/bin/

text

### Windows

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide recommends configuring long-lived access keys and using non-interactive command-line flags that place secrets directly on the shell command line. This can expose credentials through shell history, process listings, CI logs, and copied documentation snippets, which is risky in an automation-focused skill where users may paste commands verbatim.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 118)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The debug logging instruction encourages use of verbose output without warning that request details, endpoints, headers, or authentication context may be written to the console or logs. In troubleshooting and CI environments, such logs are often persisted or shared, increasing the chance of credential or sensitive metadata disclosure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/aliyun-cli-installation-guide.md (reported line 404)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The mapping table uses broad natural-language keywords such as "建站", "AI 问答", "容器", and "Serverless" that overlap with many ordinary user requests and can route users to the wrong deployment flow. In a deployment skill, misrouting is security-relevant because it can cause unintended infrastructure provisioning, wrong product selection, or execution of steps for a more privileged or costly solution than the user intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The rules explicitly allow routing on partial overlap, which weakens intent validation and increases the chance of speculative matching from loosely related text. Because this skill can initiate official solution deployment paths, permissive matching raises the risk of acting on ambiguous intent and triggering the wrong infrastructure workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document is written entirely in Chinese and does not indicate that users may choose another language or that the skill is restricted to a Chinese-language or China-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented 'Quick apply' pattern performs infrastructure creation or modification without an explicit planning/review step or a warning that the safety check is being bypassed. In an infrastructure-deployment skill, this increases the risk of unintended resource creation, cost exposure, and deployment of unsafe or misconfigured changes if an agent follows the example directly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire document, including the title and all solution descriptions, is written only in Chinese with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the full CLI command and error text to a remote Alibaba Cloud API endpoint, which can expose sensitive operational details such as resource identifiers, regions, account information, or even embedded secrets if users paste commands with credentials. Although the response is sanitized before printing, the outbound request itself is not sanitized and there is no explicit warning, consent, or minimization before transmitting potentially sensitive data off-host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This helper uses the caller's Alibaba Cloud credentials to invoke an OpenAPI endpoint for document search, even though the skill is described as a solution deployment tool. Using account credentials for ancillary search functionality unnecessarily expands the skill's privilege surface and can enable unintended authenticated API use or data access if the skill is triggered in untrusted contexts. The mismatch between purpose and capability makes this more suspicious, not less.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file implements keyword-based document search rather than deployment behavior promised by the skill metadata. This capability mismatch is dangerous because hidden or undocumented functionality undermines user trust, complicates review, and can conceal credentialed network actions that users and operators did not expect from the skill's declared purpose. In this context, the mismatch increases risk because the search operation is authenticated with cloud account credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.