alibabacloud-ecs-instance-ops
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the Alibaba Cloud CLI (aliyun-cli) and its setup script from
https://aliyuncli.alicdn.com, which is an official Alibaba Cloud domain. Per [TRUST-SCOPE-RULE], this is documented neutrally. - [REMOTE_CODE_EXECUTION]: Provides a command to download and execute a setup script:
bash -c "$(curl -fsSL --connect-timeout 10 --max-time 120 https://aliyuncli.alicdn.com/setup.sh)". While it executes remote code, the source is an official vendor domain (aliyuncli.alicdn.com). - [COMMAND_EXECUTION]: Uses the
aliyunCLI to perform lifecycle operations on ECS instances, such asdescribe-instances,run-instances,start-instance,stop-instance, anddelete-instance. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs like
InstanceName,ImageId, andNewInstanceTypewithin shell commands. It includes instructions to validate these inputs to mitigate risks, although as a capability it presents a surface for indirect injection. - [PRIVILEGE_ESCALATION]: Recommends the use of
sudofor moving binary files to/usr/local/bin/during manual Linux installation.
Recommendations
- HIGH: Downloads and executes remote code from: https://aliyuncli.alicdn.com/setup.sh - DO NOT USE without thorough review
Audit Metadata