alibabacloud-cfw-exposure-detection
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Aliyun CLI to execute cloudfw commands. These are legitimate administrative actions for the stated purpose of exposure detection. The skill includes explicit security rules to prevent the exposure of Access Key (AK) or Secret Key (SK) credentials, recommending the use of environment variables or official configuration profiles.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading the Aliyun CLI from official Alibaba Cloud domains (aliyuncli.alicdn.com). These resources are vendor-owned and trusted for the installation of the required toolset.
- [DATA_EXFILTRATION]: Network access is strictly scoped to Alibaba Cloud OpenAPI endpoints (*.aliyuncs.com). The skill explicitly forbids outbound connections to non-Alibaba external websites or arbitrary public APIs, ensuring data remains within the trusted cloud environment.
- [PROMPT_INJECTION]: The skill contains instructional headers like 'MANDATORY EXECUTION RULES' and 'CRITICAL'. These are used to guide the agent toward an automated, no-prep workflow for security auditing rather than attempting to bypass the agent's core safety guardrails.
Audit Metadata