alibabacloud-cas-ssl-cert-deploy
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Alibaba Cloud CLI installation script and binary packages from the official vendor domain (aliyuncli.alicdn.com) as part of the routine setup process.\n- [REMOTE_CODE_EXECUTION]: Executes the official vendor installation script and performs routine CLI updates using the aliyun upgrade command.\n- [COMMAND_EXECUTION]: Utilizes shell commands including aliyun CLI, ossutil, curl, and openssl to perform certificate deployment, resource management, and HTTPS verification.\n- [PROMPT_INJECTION]: Employs strict instructional constraints, such as 'ABSOLUTE RULE' and 'SESSION LOCK', to enforce safety protocols and ensure the agent does not skip mandatory human-in-the-loop (HITL) checkpoints.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from cloud resource lists and certificate details, representing an indirect injection surface.\n
- Ingestion points: Domain names and resource IDs fetched via aliyun cas list-cloud-resources and get-user-certificate-detail.\n
- Boundary markers: Includes mandatory interactive confirmation steps (hitl-confirm-resources, hitl-confirm-deployment-job) before critical API calls.\n
- Capability inventory: Subprocess execution for cloud management and network connectivity checks.\n
- Sanitization: Relies on explicit user validation of resource identifiers and certificate IDs prior to task execution.\n- [SAFE]: Explicitly prohibits the agent from reading, echoing, or requesting sensitive Alibaba Cloud credentials (AK/SK) within the conversation flow.
Audit Metadata