alibabacloud-ecs-scenario-ops

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches Alibaba Cloud CLI binaries from the official vendor domain aliyuncli.alicdn.com during the installation phase.
  • Evidence: Downloads for macOS, Linux, and Windows found in references/cli-installation-guide.md.
  • [REMOTE_CODE_EXECUTION]: Installation instructions utilize piped shell commands to download, extract, and install binaries from a trusted vendor.
  • Evidence: curl -L [...] https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xz in references/cli-installation-guide.md.
  • [COMMAND_EXECUTION]: Orchestrates cloud infrastructure through the Aliyun CLI and executes remote shell scripts on ECS instances using the Cloud Assistant feature.
  • Evidence: Multiple uses of aliyun ecs run-command in SKILL.md to resize partitions and format disks.
  • [OBFUSCATION]: Uses Base64 encoding to transmit shell command payloads via the Alibaba Cloud CLI. The decoded content was verified as benign system maintenance scripts.
  • Evidence: run-command --command-content "$(echo '...' | base64)" in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided parameters (such as RegionId, DiskId, and InstanceId) to construct shell commands executed on remote instances, creating a standard operational attack surface.
  • Evidence: Use of placeholders in SKILL.md that are populated by the agent based on user input or environment data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:10 AM