Back to skill

Security audit

Alibabacloud Wxz Website Builder

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for an Alibaba Cloud website-building workflow, but it tells the agent to silently answer later user-review forms and submit them to the cloud service without asking the user.

Install only if you are comfortable letting the agent use your Alibaba Cloud credentials to create website-builder conversations and automatically submit later requirement defaults without asking you each time. Prefer a least-privilege RAM user, review generated project data in Alibaba Cloud, and avoid using root AccessKeys or highly sensitive business requirements with this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
The skill instructs the agent to answer later human-in-the-loop prompts automatically using defaults and explicitly not ask the user. This bypasses user review for potentially material project, business, language, or feature choices, and can cause the agent to submit inferred or preselected data that the user never approved. Because these answers are sent to a remote cloud service, the issue is both an autonomy and data-submission risk.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The instruction to always force `--phase generate_prd --user-navigation generate_prd` hard-codes a state transition regardless of conversational context. Forcing workflow state can skip expected checks or user validation steps and may submit data into a later processing stage before the user intended to proceed. In an external service workflow, this reduces the agent's ability to respect actual system prompts and user consent boundaries.

Ssd 3

Medium
Confidence
95% confidence
Finding
Auto-submitting later HITL forms with default or preselected answers can silently transmit collected, inferred, or sensitive business details back to the service without user review. Even if the defaults are 'sensible,' they may encode assumptions about features, target audience, language, or references that the user would not want shared or acted upon. The risk is amplified because the skill is designed to persist conversation IDs and evidence artifacts.

Ssd 3

Medium
Confidence
96% confidence
Finding
The repeated directive to use hidden/default answers from `AskUserQuestion` events without user review creates a pattern of silent retransmission of user-related data. Hidden resumes and automatic reuse of `answers` fields can propagate data the user did not manually provide in that round, making auditing and consent difficult. In a multi-step cloud workflow, this increases the chance of over-sharing and unintended processing.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.