alibabacloud-suggest-cli

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local script check_cli.py to validate generated commands before presenting them to the user. This script runs via python3 but is part of the skill's own package and is used purely for static analysis of command strings written to /tmp/aliyun-cli-commands.sh.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to suggest commands only and 'do not execute unless asked', which is a safety guardrail for the CallCLI tool.
  • [SAFE]: All external tools referenced in allowed-tools belong to the alibabacloud-core MCP plugin, which is the official provider for this skill's vendor (aliyun).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:11 AM
Security Audit — agent-trust-hub — alibabacloud-suggest-cli