alibabacloud-agent-toolkit-install

Fail

Audited by Snyk on Jul 5, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). Mostly official Alibaba domains (aliyun.com / alicdn.com) which are generally legitimate, but the presence of direct downloadable archives/executables and pipe-to-shell installer scripts (aliyuncli install.sh, astral.sh install.sh/install.ps1) — plus a third‑party host (astral.sh) — are high‑risk patterns that should be verified before running.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). Step 7 runs npx openplugin aliyun/alibabacloud-agent-toolkit, which at runtime downloads/installs an outsider-authored package from the public npm registry and thus can feed its README/metadata/code text into the agent’s LLM context via plugin installation.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 5, 2026, 09:15 AM
Issues
3
Security Audit — snyk — alibabacloud-agent-toolkit-install