Back to skill

Security audit

alibabacloud-wuying-console

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent as an Alibaba Cloud WUYING admin helper, but it exposes broad high-impact CLI operations including credential/token retrieval, remote command execution, destructive resource changes, and tenant skill/security administration.

Install only for trusted Alibaba Cloud WUYING administrators using a least-privilege Aliyun profile. Review any request involving passwords, tokens, login credentials, remote command execution, tenant skill/security settings, deletes, resets, releases, or rebuilds, and require explicit confirmation with exact targets before allowing those operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad operational skill for querying and managing WUYING resources such as cloud computers, browsers, users, policies, images, terminals, sessions, and reports. The supplied code chunk does something narrower and materially different: it audits installed Aliyun CLI plugins and builds a deterministic catalog of available commands from --help-all output. It validates plugin metadata, supported API versions, and writes a JSON reference file. While this is related to local WUYING CLI setup/troubleshooting, it does not actually execute resource-level WUYING operations or manage the listed resource types. Therefore the code only partially aligns with the description and the primary purpose is mismatched.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The catalog includes commands that expose sensitive secrets and credentials, including user passwords and temporary authentication tokens. Even read-style access to such material can immediately enable account compromise, session hijacking, data exfiltration, or downstream privilege escalation if invoked by an untrusted or manipulated agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The presence of the run-command operation enables remote execution of PowerShell or batch scripts on cloud computers, which is a direct code-execution primitive. In an agent setting, this is especially dangerous because any prompt confusion, policy bypass, or malicious instruction can be escalated into arbitrary command execution on managed endpoints.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to run shell commands and read local files, but it does not declare any tool scope such as allowed tools or permissions. This creates an authorization gap where an orchestrator may grant broader execution capability than users expect, increasing the risk of unintended command execution, local environment inspection, or plugin installation workflows.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/authentication.md (reported line 28)May include surrounding context.

md
- Do not create a second credential store for this skill.
- Do not silently switch accounts or profiles. State which profile/account context will be used before a mutation.
- For unattended environments, use the credential method approved by the customer's security policy; do not convert a personal login into a long-lived shared credential.
- If authentication expires, stop and request reauthentication. Do not fall back to a different profile without approval.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command catalog materially exceeds the skill’s declared scope by bundling broad Elastic Desktop Service and workspace-administration operations. This increases the reachable attack surface from routine WUYING resource management to tenant-wide administration, making it easier for an agent or prompt injection to invoke unrelated high-risk actions under the guise of normal skill use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Identity-skill administration commands such as setting skill permissions, security, and tenant enablement are unrelated to ordinary WUYING resource management and can be used to alter who can use skills or weaken policy boundaries. In an agent environment, exposing meta-administrative controls creates a privilege-management path that can be abused for lateral expansion of access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/command-catalog.json (reported line 3605)May include surrounding context.

json
},
        {
          "name": "untag-resources",
          "description": "Removes tags from cloud desktops. After a tag is removed, if the tag is not added to any cloud desktop, the tag is automatically deleted",
          "api_versions": [
            "2020-09-30"
          ],

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/check_environment.py (reported line 92)May include surrounding context.

python
command: list[str],
    timeout: int | None = None,
) -> subprocess.CompletedProcess[str]:
    return subprocess.run(
        command,
        check=False,
        stdout=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_command_catalog.py (reported line 47)May include surrounding context.

python
def run_command(command: list[str]) -> str:
    completed = subprocess.run(
        command,
        check=False,
        stdout=subprocess.PIPE,

Static analysis

No suspicious patterns detected.