Back to skill

Security audit

alibabacloud-waf-domain-cert-status-check

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main audit workflow is read-only and coherent, but its setup guidance expands into privileged, self-updating CLI/plugin installation and broad credential configuration that warrants review before use.

Install only if you are comfortable with an agent-assisted workflow that uses your Alibaba Cloud profile to read WAF domain and certificate metadata. Prefer a preinstalled, administrator-managed Aliyun CLI, avoid curl-to-shell and self-update paths, disable broad auto plugin behavior where possible, and use least-privilege temporary or role-based credentials limited to the documented WAF/CAS read actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Documenting a self-update capability for the CLI introduces a software supply-chain and behavior-change risk in agent environments, because future executions may run a materially different binary than the one originally reviewed. For a tightly scoped skill, encouraging self-update reduces reproducibility and can bypass change-control expectations.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 78)May include surrounding context.

aliyun version

text

### Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The explicit aliyun upgrade command operationalizes the self-modification concern by instructing users or automation to mutate the installed tool at runtime. In a skill context, that can create non-deterministic behavior and expand supply-chain exposure beyond the reviewed artifact set.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 80)May include surrounding context.

Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

bash
aliyun upgrade

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is for a narrowly scoped read-only WAF certificate audit skill, but it embeds a broad Alibaba Cloud CLI administration guide covering generic auth modes, ECS commands, plugin installation, troubleshooting, and wider cloud operations. In an agent context, this materially expands the operational surface and can steer users or automation toward unnecessary privileged setup unrelated to certificate status checking.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section teaches users how to configure long-lived AccessKey credentials and multiple privileged authentication modes far beyond what a read-only WAF cert check needs. In a skill package, such guidance can normalize broad credential provisioning and cause operators to hand the agent durable cloud access that could be abused if the skill or surrounding workflow is compromised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly expects powerful capabilities including shell execution, file reads, environment access, and networked CLI/API use, but it declares no explicit tool scope or allowed-tools boundary. That omission weakens least-privilege controls and can let an agent invoke broader capabilities than reviewers or policy engines expect.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
"expiry not retrieved", listed as an item needing manual review — never counted as healthy.
6. **The WAF major version decides the API path and cannot be inferred from dates or names.** Honor
   an explicit `3.0`, `2.0`, or `both` scope. A request that says "both" still gets one scope-confirmation
   HITL unless it also says "start directly / no confirmation". If region is missing and the request
   contains a **conditional** version phrase (e.g. "如果存在多个版本,我选 3.0" — note "如果/if"),
   that wording is a conditional preference, **NOT a definitive selection**: first ask only for region
   and wait; after `DescribeInstance` returns, you MUST issue a **second, separate HITL turn** asking

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
"expiry not retrieved", listed as an item needing manual review — never counted as healthy.
6. **The WAF major version decides the API path and cannot be inferred from dates or names.** Honor
   an explicit `3.0`, `2.0`, or `both` scope. A request that says "both" still gets one scope-confirmation
   HITL unless it also says "start directly / no confirmation". If region is missing and the request
   contains a **conditional** version phrase (e.g. "如果存在多个版本,我选 3.0" — note "如果/if"),
   that wording is a conditional preference, **NOT a definitive selection**: first ask only for region
   and wait; after `DescribeInstance` returns, you MUST issue a **second, separate HITL turn** asking

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
"expiry not retrieved", listed as an item needing manual review — never counted as healthy.
6. **The WAF major version decides the API path and cannot be inferred from dates or names.** Honor
   an explicit `3.0`, `2.0`, or `both` scope. A request that says "both" still gets one scope-confirmation
   HITL unless it also says "start directly / no confirmation". If region is missing and the request
   contains a **conditional** version phrase (e.g. "如果存在多个版本,我选 3.0" — note "如果/if"),
   that wording is a conditional preference, **NOT a definitive selection**: first ask only for region
   and wait; after `DescribeInstance` returns, you MUST issue a **second, separate HITL turn** asking

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
"expiry not retrieved", listed as an item needing manual review — never counted as healthy.
6. **The WAF major version decides the API path and cannot be inferred from dates or names.** Honor
   an explicit `3.0`, `2.0`, or `both` scope. A request that says "both" still gets one scope-confirmation
   HITL unless it also says "start directly / no confirmation". If region is missing and the request
   contains a **conditional** version phrase (e.g. "如果存在多个版本,我选 3.0" — note "如果/if"),
   that wording is a conditional preference, **NOT a definitive selection**: first ask only for region
   and wait; after `DescribeInstance` returns, you MUST issue a **second, separate HITL turn** asking

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A read-only certificate audit skill should not require environment mutation such as installing/updating CLI components, enabling auto-plugin installation, or changing host configuration. These steps expand the trust boundary, introduce supply-chain risk, and create opportunities for unintended code execution or plugin retrieval beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill instructs use of sudo to move a binary into /usr/local/bin, introducing privileged host modification as part of a certificate audit workflow. Combining elevated execution with downloaded tooling materially increases the blast radius if the binary is malicious, tampered with, or simply the wrong artifact.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
> [MUST] Verify: `aliyun version` — must be >= 3.3.3.
> - **Preferred (no remote script execution):** download `https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz`
>   (macOS: `aliyun-cli-macosx-latest-{amd64|arm64}.tgz`), `tar tzf` to inspect, `tar xzf`, `sudo mv aliyun /usr/local/bin/`.
> - **Alternative:** `/bin/bash -c "$(curl -fsSL --connect-timeout 10 --max-time 120 https://aliyuncli.alicdn.com/setup.sh)"`
> - **Update (CLI >= 3.3.5):** `aliyun upgrade`. Full instructions: `references/cli-installation-guide.md`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill includes a one-liner that downloads and executes a remote shell script via curl and bash. This is a classic remote-code-execution and supply-chain hazard: if the upstream script, transport, or endpoint is compromised, the host running the skill executes attacker-controlled code.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 431)May include surrounding context.

md
| Error | Action | Behaviour |
|-------|--------|-----------|
| Permission (`Forbidden`/RAM) | **HITL** | Present required permissions, ask user to grant, **wait** for reply. After reply retry the exact failed command. |
| Parameter (`InvalidParameter`) | **TERMINATE** | Report the error and stop silently — no follow-up question, no retry, no asking user to fix. Exceptions: WAF 3.0 named-ID reconciliation; an `InvalidParameter` / not-found answer to the `probe.waf-cert-check.local` or `--cert-id 0` probe is expected — continue. |
| Throttling (`Throttling.User`/429) | **RETRY** | Retry the **identical command verbatim** (same parameters, same API version, same endpoint — changing anything is "auto-correction", not retry) with backoff 2 s → 4 s → 8 s. After 3 failures mark "not retrieved — throttled". |
| CAS `InternalError` / 5xx (real CertId **or** `--cert-id 0` probe) | **HITL** | NOT throttling and NOT "expected": zero retries. Immediately end the turn with a short question — CAS internal error, expiry not retrieved, ask the user to check CAS status and reply whether to retry. Before the reply: no further call, no script, no final report. |
| `ComboError` (no package) | **CONTINUE** | Record "no WAF 2.0 package (not RAM)", proceed with remaining 2.0 commands (`describe-domain-names` mandatory). |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

wget -q --connect-timeout=10 --read-timeout=120 --tries=3 https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz tar tzf aliyun-cli-macosx-latest-amd64.tgz # list contents and confirm before extracting tar xzf aliyun-cli-macosx-latest-amd64.tgz sudo mv aliyun /usr/local/bin/

text

**ARM64**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 27)May include surrounding context.

wget -q --connect-timeout=10 --read-timeout=120 --tries=3 https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz tar tzf aliyun-cli-macosx-latest-amd64.tgz # list contents and confirm before extracting tar xzf aliyun-cli-macosx-latest-amd64.tgz sudo mv aliyun /usr/local/bin/

text

**ARM64**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide instructs users to pass access-key material directly on the command line, which can expose secrets through shell history, terminal logging, process inspection, and CI job records. This is especially risky in automation or shared environments where command invocations may be captured centrally.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 106)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Exporting cloud credentials as environment variables without caution can leak them to child processes, debug output, crash dumps, CI logs, and misconfigured observability tooling. In an agent or automation setting, environment-based secrets are commonly overexposed and persist longer than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference includes unrelated verification, debugging, ECS, region discovery, and plugin-management commands outside the WAF certificate checking use case. While not directly malicious, this scope creep increases the chance an agent or user performs unnecessary cloud enumeration or operational changes under credentials provisioned for the skill.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 398)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/related-commands.md (reported line 85)May include surrounding context.

md
| Topic | Link |
|-------|------|
| DescribeDomains (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomains |
| DescribeDomainDetail (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomainDetail |
| DescribeDomainNames (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeDomainNames |
| DescribeCertificates (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeCertificates |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/related-commands.md (reported line 86)May include surrounding context.

md
| Topic | Link |
|-------|------|
| DescribeDomains (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomains |
| DescribeDomainDetail (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomainDetail |
| DescribeDomainNames (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeDomainNames |
| DescribeCertificates (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeCertificates |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/related-commands.md (reported line 87)May include surrounding context.

md
| Topic | Link |
|-------|------|
| DescribeDomains (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomains |
| DescribeDomainDetail (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomainDetail |
| DescribeDomainNames (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeDomainNames |
| DescribeCertificates (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeCertificates |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/related-commands.md (reported line 88)May include surrounding context.

md
| Topic | Link |
|-------|------|
| DescribeDomains (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomains |
| DescribeDomainDetail (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomainDetail |
| DescribeDomainNames (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeDomainNames |
| DescribeCertificates (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeCertificates |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/related-commands.md (reported line 89)May include surrounding context.

md
| Topic | Link |
|-------|------|
| DescribeDomains (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomains |
| DescribeDomainDetail (3.0) | https://api.aliyun.com/document/waf-openapi/2021-10-01/DescribeDomainDetail |
| DescribeDomainNames (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeDomainNames |
| DescribeCertificates (2.0) | https://api.aliyun.com/document/waf-openapi/2019-09-10/DescribeCertificates |

Static analysis

No suspicious patterns detected.