alibabacloud-ecs-instance-ops

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads the Alibaba Cloud CLI (aliyun-cli) and its setup script from https://aliyuncli.alicdn.com, which is an official Alibaba Cloud domain. Per [TRUST-SCOPE-RULE], this is documented neutrally.
  • [REMOTE_CODE_EXECUTION]: Provides a command to download and execute a setup script: bash -c "$(curl -fsSL --connect-timeout 10 --max-time 120 https://aliyuncli.alicdn.com/setup.sh)". While it executes remote code, the source is an official vendor domain (aliyuncli.alicdn.com).
  • [COMMAND_EXECUTION]: Uses the aliyun CLI to perform lifecycle operations on ECS instances, such as describe-instances, run-instances, start-instance, stop-instance, and delete-instance.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs like InstanceName, ImageId, and NewInstanceType within shell commands. It includes instructions to validate these inputs to mitigate risks, although as a capability it presents a surface for indirect injection.
  • [PRIVILEGE_ESCALATION]: Recommends the use of sudo for moving binary files to /usr/local/bin/ during manual Linux installation.
Recommendations
  • HIGH: Downloads and executes remote code from: https://aliyuncli.alicdn.com/setup.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 06:09 AM