alibabacloud-aes-sysom-lingjun-diagnosis
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and most capabilities are coherent with Alibaba Cloud SysOM diagnosis and DingTalk alert setup, and its API/data flow appears to target official Alibaba services rather than a credential-harvesting proxy. The main security concern is install/execution trust: it updates plugins, enables auto-plugin install, and executes local helper scripts whose contents are not provided here, so the full credential and network behavior of those scripts cannot be verified from the skill text alone. This is not enough to call malicious, but it is higher-risk than a pure documentation skill.
Confidence: 84%Severity: 61%
Audit Metadata