Back to skill

Security audit

alibabacloud-waf-certchain-complete

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its certificate-chain repair purpose, but it includes unsafe CLI installation guidance and a hidden remote TLS probing capability that contradicts the stated scope.

Review before installing. Prefer installing Aliyun CLI through a trusted package manager or verified release instead of curl-to-bash, avoid enabling automatic plugin installation unless you accept that trust boundary, use a dedicated least-privilege WAF read-only profile, and do not use the hidden remote-probing script flags unless you explicitly intend outbound TLS connections.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (19)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This command fetches a script from an external server and executes it immediately, creating a direct remote code execution path on the operator's workstation. In a skill intended to help administer WAF certificates, compromising the operator environment could expose cloud credentials and enable broader infrastructure abuse.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 6)May include surrounding context.

Install / Update

bash
curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

Verify:

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The use of '| bash' is a dangerous execution chain because it suppresses an opportunity to inspect downloaded content before running it. If the upstream script is altered maliciously, execution occurs immediately with the user's privileges.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 6)May include surrounding context.

Install / Update

bash
curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

Verify:

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The Linux x86_64 example repeats the same unsafe pattern of downloading and executing a remote script in one step. Because this is operational documentation for cloud administration tooling, successful exploitation could lead to credential theft or malicious changes in the target environment.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 55)May include surrounding context.

bash
# x86_64
curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

# aarch64
curl -fsSL https://aliyuncli.alicdn.com/setup_arm64.sh | bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This line chains network retrieval directly into shell execution, which is a well-known unsafe pattern for administrative environments. In the context of cloud CLI setup, exploitation could compromise the local host and any configured cloud accounts.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 55)May include surrounding context.

bash
# x86_64
curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

# aarch64
curl -fsSL https://aliyuncli.alicdn.com/setup_arm64.sh | bash

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The ARM64 installation path also executes an externally fetched script without inspection or verification, carrying the same remote code execution risk. The duplicated pattern increases exposure across platforms rather than isolating risk to one environment.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

aarch64

curl -fsSL https://aliyuncli.alicdn.com/setup_arm64.sh | bash

text

### Windows

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The ARM64 command uses the same chaining pattern, preserving immediate execution risk from remote content. Because the document is meant for WAF-related operations, a compromised installer could be used to steal credentials or tamper with security infrastructure workflows.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 58)May include surrounding context.

curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash

aarch64

curl -fsSL https://aliyuncli.alicdn.com/setup_arm64.sh | bash

text

### Windows

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill invokes shell commands, reads local files, writes output files, and performs network retrieval, but it does not declare an explicit tool/permission scope in structured metadata. That mismatch weakens policy enforcement and review because an execution environment may grant broader capabilities than the skill contract communicates, increasing the chance of unintended file, shell, or network access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
| Local PEM only | Skip all cloud setup and run the local checker |
| WAF `InstanceId` only | Run `DescribeCerts`; report incomplete certificate identifiers and request the affected PEM before repair |
| Both `InstanceId` and PEM | Query WAF status, then use the supplied PEM for repair |
| Neither | State, in one declarative sentence, that you need a WAF 3.0 `InstanceId` or a local PEM path, explicitly noting you will not guess a target, list domains/instances, or fabricate certificate data until the user supplies it, then end the turn on that statement. Do not phrase it as a question, do not use a trailing question mark, do not ask the user to reply, and do not pause, poll, wait, or call any interactive/blocking tool. Never proceed on assumed or invented values. |

Requesting missing input (or a target selection) is required behavior and is NOT the same as blocking: say in one declarative sentence exactly what you need, then stop the turn. Do NOT end with a question mark, do NOT explicitly ask the user to reply, and do NOT pause, poll, wait, or call any interactive/blocking tool — those are what turn a legitimate input request into a blocking stall. Fabricating data to avoid requesting the input is equally forbidden.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs users to pipe a remotely fetched script directly into bash without any warning or integrity verification. If the hosting endpoint, CDN path, or network trust boundary is compromised, arbitrary code will execute immediately on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Enabling automatic plugin installation permits the CLI to download and execute additional code implicitly, expanding the trust boundary beyond the base CLI. Without warning or restrictions, users may unknowingly allow execution of unreviewed plugins or plugin updates.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/ram-policies.md (reported line 26)May include surrounding context.

md
When `DescribeCerts` fails with `Forbidden.RAM`, `NoPermission`, or `not authorized`, terminate immediately without retrying. State that the query could not be completed because read-only `yundun-waf:DescribeCerts` permission is missing, then end the turn. Do not request authorization, wait for confirmation, change credentials, or continue into local repair. Without a successful response, certificate-chain status remains unknown.

The policy above documents the prerequisite only; it is not an instruction to grant permissions during error recovery. Never request certificate create/deploy permissions and never ask the user to paste AK/SK values into the conversation.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fix_certchain.py (reported line 33)May include surrounding context.

python
def run_openssl(args, stdin_data=None):
    """Run an openssl command and return (stdout, stderr, returncode)."""
    proc = subprocess.run(
        ["openssl"] + args,
        input=stdin_data,
        capture_output=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script contains an undocumented capability to probe arbitrary remote hosts and retrieve live certificate chains, which exceeds the stated local-PEM repair scope. Hidden network-capable functionality increases misuse risk because operators may invoke the skill under the assumption it only processes local files, causing unexpected outbound connections to attacker-chosen targets.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fix_certchain.py (reported line 207)May include surrounding context.

python
target = ip or domain
    try:
        cmd = ["s_client", "-connect", f"{target}:{port}", "-servername", domain, "-showcerts"]
        proc = subprocess.run(
            ["openssl"] + cmd,
            input=b"\n",
            capture_output=True,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code comments claim remote-probe flags are not part of the supported interface, yet the parser still accepts and executes them. This mismatch is dangerous because it conceals network-active behavior from users and reviewers, undermining trust boundaries and making unintended outbound access more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template response is hard-coded in Chinese: "上传完成后请回复‘已上传’,我会继续验证证书链状态。" This enforces a specific language for user interaction, which can violate language/locale policy unless the user has opted into that language or the skill is explicitly region/language-scoped.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The credential setup instructions normalize entering cloud credentials without warning that access keys are sensitive secrets. This increases the chance users will expose keys through shell history, screenshots, shared terminals, or insecure profile handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Remote certificate probing initiates outbound network connections but the documented interface does not clearly warn users of that side effect. In a skill presented as a local certificate checker/fixer, undisclosed network access can violate operator expectations, leak target information, and expand the attack surface for SSRF-like misuse even if some destination controls exist.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The auto-fix path fetches certificate-derived URLs over the network and may write repaired PEM output, but the top-level usage text does not clearly disclose these side effects. Even though the code applies meaningful URL safety checks, undisclosed network/file-write behavior can still surprise users and be abused for policy bypass or unintended data flow in restricted environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.