Back to skill

Security audit

Alibabacloud Starops Chat

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent STAROps diagnostic client, but it needs Review because a configurable endpoint can redirect signed Alibaba Cloud requests and incident context to an arbitrary host.

Install only in trusted projects and review any .starops/config.json before running. Prefer the default Alibaba Cloud STAROps endpoint, avoid setting STAROPS_AGENT_ENDPOINT unless you fully trust the destination, use least-privilege RAM credentials limited to CreateThread/CreateChat, and do not include secrets or regulated incident data in questions unless your organization has approved STAROps for that data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/call_starops_agent.py:371
Finding

Unvalidated Endpoint Override Can Redirect Signed STAROps Requests

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:1
Finding

Dependency Installation Does Not Enforce Package Integrity Hashes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (9)

Context Leakage

High
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs the agent to extract and reuse thread IDs and to surface a STAROPS_URL tied to an investigation thread. Those identifiers can preserve and expose prior diagnostic context, potentially allowing sensitive incident data, service topology, or prior conversation contents to be linked across turns or disclosed to unintended recipients if thread values are logged, echoed, or reused in the wrong context.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

text

**Thread Management:**
- Extract thread ID from output
- Use the printed `STAROPS_URL` when the user needs to inspect the same thread in the STAROps console
- Always pass `--thread "<id>"` for related follow-up questions to preserve context

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/call_starops_agent.py (reported line 911)May include surrounding context.

python
, "text", "value", "answer"):
        value = message.get(field)
        if isinstance(value, str) and value.strip():
            parts.append(value.strip())
    items = message.get("items")
    if isinstance(items, list):
        parts.extend(extract_text_parts(items))
    contents = message.get("contents")
    if isinstance(contents, list):
        parts.extend(extract_text_parts(contents))
    tools = message.get("tools")
    if isinstance(tools, list):
        parts.extend(extract_text_tool_parts(tools))
    return "\n".join(dedupe_preserve_order(parts)).strip()


def extract_tool_records(message: Mapping[str, Any]) -> list[ToolRecord]:
    raw_tools: list[Any] = []
    tools = message.get("tools")
    if isinstance(tools, list):
        raw_tools.extend(tools)

    items = message.get("items")
    if isinstance(items, list):
        for item in items:
            if isinstance(item, dict) and isinstance(item.get("tools"), list):
                raw_tools.extend(item["tools"])

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs sensitive operations involving environment variables, local config file reads, and outbound network access, but it declares no explicit tool scope or permission boundaries. This increases the chance that an invoking agent will grant broader-than-necessary capabilities, making credential exposure or unintended external data transmission harder to govern and audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata lists usage and triggers using Chinese phrases only, which can impose a language/locale expectation on users without stating that Chinese is required or offering an alternative language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 97)May include surrounding context.

CORRECT — Project config file supplies required values

bash
mkdir -p .starops
cat > .starops/config.json <<'JSON'
{
  "employeeId": "<your-digital-employee-id>",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly states that user questions and workspace/project variables are sent to a remote Alibaba Cloud STAROps endpoint, but it does not mention this external transmission as a user-facing privacy or data-sharing warning. In a diagnostic skill, prompts, incident details, service names, and workspace metadata may contain sensitive operational or business information, so silent forwarding to a third-party service creates a real data exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script transmits the user's question and workspace/project context to a remote Alibaba Cloud STAROps endpoint, but the CLI flow does not present an explicit warning or confirmation that potentially sensitive incident, service, or topology data will leave the local environment. In an AIOps diagnostic skill, prompts often contain internal infrastructure details, making accidental data disclosure more likely and more sensitive than in a generic chatbot context.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.4 — 2 advisory(ies): CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2026-25645 (Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract)

Medium
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency pin requests==2.32.4 matches a version identified by the scanner as affected by a known vulnerability fixed in requests 2.33.0. Even though the issue is in a utility path (extract_zipped_paths()), including a vulnerable library in an incident-diagnosis skill is still risky because agent code may process remote resources or archives indirectly through supporting code paths, and future code changes could expose the vulnerable function.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/call_starops_agent.py (reported line 773)May include surrounding context.

python
def call_or_none(obj: Any, method_name: str) -> Any:
    method = getattr(obj, method_name, None)
    if method is None:
        return None
    return method()

Static analysis

No suspicious patterns detected.