Back to skill

Security audit

alibabacloud-waf-openapi-error-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

The core WAF diagnosis tool is mostly read-only, but the package also gives broad CLI installation, plugin-update, and credential-configuration guidance that goes beyond its no-credentials diagnostic purpose.

Review before installing. Prefer using only the credential-free metadata diff path. Avoid the curl-to-bash installer unless you independently trust the source, do not configure long-lived AccessKeys just for this diagnosis, and limit any Aliyun profile to temporary or read-only credentials if optional live read checks are needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code largely matches the declared read-only diagnostic intent: it never sends a real WAF API call, uses a public metadata endpoint, compares provided params to the official spec, and optionally checks CLI flags. However, there are material gaps versus the description. Most importantly, the description says it covers both WAF generations across CLI/SDK/raw RPC, but the code explicitly states that public metadata only exists for 2019-09-10 and 2021-10-01 and exits with an error for other WAF 2.0 versions rather than diagnosing them. Also, the description promises to 'return a corrected call in the same channel,' but the implementation only prints specs/findings and does not construct a corrected SDK/CLI/raw RPC invocation. These are substantive description-behavior mismatches rather than minor implementation details.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 78)May include surrounding context.

aliyun version

text

### Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 80)May include surrounding context.

Self-Update (CLI >= 3.3.5)

Once the CLI is at version 3.3.5 or newer, routine updates can use the built-in self-update subcommand instead of re-running the install script:

bash
aliyun upgrade

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This guide materially expands the skill from a read-only WAF error-diagnosis helper into a general Alibaba Cloud CLI onboarding and authenticated operations workflow. That scope creep is dangerous because it normalizes installing tools, configuring persistent credentials, and performing arbitrary cloud actions that are unnecessary for the stated no-credentials core diff use case.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to be read-only and to need no credentials for its core function, yet the guide immediately instructs users to configure long-lived access keys and test authenticated API access. That contradiction can mislead users or downstream agents into escalating privileges unnecessarily and exposing secrets for a task that should not require them.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document teaches users how to acquire, store, and use Alibaba Cloud credentials even though the skill metadata says the core diagnosis flow needs no credentials. In an agent setting, this increases the chance of credential harvesting, unnecessary secret persistence, and use of privileged sessions beyond the intended task.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs the agent to use shell, file reads, environment variables, and network access, but it does not declare an explicit tool/permission scope. That creates unnecessary ambient authority: if this skill is enabled in an environment with broad tool access, the agent can perform actions beyond the minimum needed, increasing the blast radius of prompt injection or operator error.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file contains a natural-language policy constraint that forces a specific response language based on detected ticket language. Under the stated rule, locale or language requirements should offer a choice or be clearly justified as region-specific; this instruction does not provide opt-in or user selection.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The installation instructions include privileged execution via both sudo mv and a remote-script pattern bash -c "$(curl ...)". Encouraging elevated installation and direct remote script execution is dangerous because a compromised download source, MITM, or copied command can lead to arbitrary code execution with high privileges on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
> [MUST] Verify: `aliyun version` — must be >= 3.3.3.
> - **Preferred (no remote script execution):** download `https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz`
>   (macOS: `aliyun-cli-macosx-latest-{amd64|arm64}.tgz`), `tar tzf` to inspect, `tar xzf`, `sudo mv aliyun /usr/local/bin/`.
> - **Alternative:** `/bin/bash -c "$(curl -fsSL --connect-timeout 10 --max-time 120 https://aliyuncli.alicdn.com/setup.sh)"`
> - **Update (CLI >= 3.3.5):** `aliyun upgrade`. Full instructions: `references/cli-installation-guide.md`.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

Forbidden.RAM 属于 RAM 权限、非参数、out-of-scope;请提供 Action/接口名和 API version/版本,以便转交 ram-permission-diagnose 生成最小权限建议。

text
The throttling response is final: do not ask any question and do not mention spec lookup, parameter comparison,
or phases. The RAM response is the only out-of-scope branch that waits for Action and version; do not run any
command before or after that question in this skill.

### Phase 3: Fetch the authoritative spec (canonical calls #0 and #1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill sends request metadata and user-supplied parameters to an external endpoint, which is an external data transmission boundary. Even if intended for public API metadata lookup, the skill also permits passing customer params into the diagnosis workflow, so sensitive or proprietary request contents could be disclosed off-box without a strong minimization guarantee.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
non-empty. Keep `scripts/diagnose_openapi_error.py` relative (no `./`). Keep the flag order
  `--version … --action …`. Add `--channel cli` only **after** `--action <Action>` if you need CLI flag names.
- Equivalent raw sources: the metadata endpoint
  `https://api.aliyun.com/meta/v1/products/waf-openapi/versions/{version}/apis/{Action}/api.json`, or
  `aliyun waf-openapi <kebab-action> [--api-version 2019-09-10] --help`.

Read the exit-`2` messages — three distinct root causes, and **do not loop retrying versions**:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

md
- Explicit request to verify/validate/run dry-run → invoke exactly one CLI command through the command tool.
  Merely printing or recommending the command does not satisfy the request. This local dry-run is allowed for
  write-named actions; `--cli-dry-run` must be present in the command actually invoked.
- Any explicit refusal, including "direct report", "no verification", or equivalent → skip Phase 5 completely.
  Do not invoke, propose, or mention a dry-run in the final report.
- No explicit preference → do not run it.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction "Reply in the customer's language (Chinese for domestic tickets)" imposes a locale choice based on ticket category rather than explicit user preference. The rule set flags language or locale constraints unless the skill offers a user choice or clearly justified documented exception.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Advertising support for installing and using all published product plugins broadens the operational surface far beyond WAF OpenAPI error diagnosis. Even if informational, it encourages unrelated capability expansion inside a narrowly scoped skill, which is risky in agentic environments.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

wget -q --connect-timeout=10 --read-timeout=120 --tries=3 https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz tar tzf aliyun-cli-macosx-latest-amd64.tgz # list contents and confirm before extracting tar xzf aliyun-cli-macosx-latest-amd64.tgz sudo mv aliyun /usr/local/bin/

text

**ARM64**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 27)May include surrounding context.

wget -q --connect-timeout=10 --read-timeout=120 --tries=3 https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz tar tzf aliyun-cli-macosx-latest-amd64.tgz # list contents and confirm before extracting tar xzf aliyun-cli-macosx-latest-amd64.tgz sudo mv aliyun /usr/local/bin/

text

**ARM64**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples show direct configuration of long-lived access keys without an adjacent warning that these secrets may be stored locally and exposed through shell history, screenshots, backups, or misconfigured file permissions. In security-sensitive automation contexts, that omission increases the likelihood of credential leakage.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

Telling users to create a new AccessKey pair and save the secret encourages persistence of reusable credentials for a skill whose core function does not require them. In context, this expands the session and secret footprint unnecessarily, making compromise of notes, terminals, or local files more consequential.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 106)May include surrounding context.

md
1. Log in to Aliyun Console: https://ram.console.aliyun.com/
2. Navigate to: AccessKey Management
3. Create a new AccessKey pair
4. Save the secret immediately — it's only shown once

### Configuration Modes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Showing a config file containing plaintext access key material without an immediate sensitivity warning can normalize unsafe storage of reusable credentials. Readers may copy the pattern into real systems without understanding the need for strict file protection and secret lifecycle controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Exporting cloud credentials as environment variables without a nearby warning ignores common leakage paths such as child processes, debug output, crash reports, CI logs, and shell history. For an agent skill, that is especially risky because automated tooling often propagates environment state broadly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 398)May include surrounding context.

bash
# Restrict permissions
chmod 600 ~/.aliyun/config.json

Troubleshooting

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The snippet constructs request = open_api_models.OpenApiRequest(...) and documents query usage for diagnosing/fixing calls, but then invokes client.call_api(params, util_models.RuntimeOptions()) without supplying that request. This directly contradicts the example's apparent intent and would not perform the parameterized call shown in the surrounding documentation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
Map the `Code` to a class using the error-code map (linked from SKILL.md).

**Pass criteria**: parameter-class → continue. For `Throttling*`, give final rate-limit guidance without
asking for action/version or running tools. For `Forbidden*` / `NoPermission`, identify RAM/out-of-scope and
ask for both Action and version solely for least-privilege routing, then wait without running tools. Other
non-parameter classes → state the class, route, and stop.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/error-code-map.md (reported line 47)May include surrounding context.

md
Map the `Code` to a class using the error-code map (linked from SKILL.md).

**Pass criteria**: parameter-class → continue. For `Throttling*`, give final rate-limit guidance without
asking for action/version or running tools. For `Forbidden*` / `NoPermission`, identify RAM/out-of-scope and
ask for both Action and version solely for least-privilege routing, then wait without running tools. Other
non-parameter classes → state the class, route, and stop.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 27)May include surrounding context.

md
Map the `Code` to a class using the error-code map (linked from SKILL.md).

**Pass criteria**: parameter-class → continue. For `Throttling*`, give final rate-limit guidance without
asking for action/version or running tools. For `Forbidden*` / `NoPermission`, identify RAM/out-of-scope and
ask for both Action and version solely for least-privilege routing, then wait without running tools. Other
non-parameter classes → state the class, route, and stop.

Static analysis

No suspicious patterns detected.