alibabacloud-ecs-scenario-ops
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches Alibaba Cloud CLI binaries from the official vendor domain
aliyuncli.alicdn.comduring the installation phase. - Evidence: Downloads for macOS, Linux, and Windows found in
references/cli-installation-guide.md. - [REMOTE_CODE_EXECUTION]: Installation instructions utilize piped shell commands to download, extract, and install binaries from a trusted vendor.
- Evidence:
curl -L [...] https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz | tar xzinreferences/cli-installation-guide.md. - [COMMAND_EXECUTION]: Orchestrates cloud infrastructure through the Aliyun CLI and executes remote shell scripts on ECS instances using the Cloud Assistant feature.
- Evidence: Multiple uses of
aliyun ecs run-commandinSKILL.mdto resize partitions and format disks. - [OBFUSCATION]: Uses Base64 encoding to transmit shell command payloads via the Alibaba Cloud CLI. The decoded content was verified as benign system maintenance scripts.
- Evidence:
run-command --command-content "$(echo '...' | base64)"inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided parameters (such as RegionId, DiskId, and InstanceId) to construct shell commands executed on remote instances, creating a standard operational attack surface.
- Evidence: Use of placeholders in
SKILL.mdthat are populated by the agent based on user input or environment data.
Audit Metadata