alibabacloud-dataphin-skills

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suite references official Alibaba Cloud installation scripts and binaries from aliyuncli.alicdn.com and GitHub releases. It also depends on official Python SDKs such as alibabacloud-dataphin-public20230630 and well-known libraries like PyYAML. These sources are verified as trusted vendor resources.
  • [COMMAND_EXECUTION]: The suite facilitates the execution of SQL, Shell, and Python scripts within the Dataphin environment. Commands are routed through the aliyun CLI plugin. This behavior is consistent with the primary purpose of a data engineering and operations tool.
  • [PROMPT_INJECTION]: The skill implements strict internal instructions to ensure the deployment environment (public cloud vs. standalone) remains opaque to the user during credential collection. It also includes a 'CLI Version Gate' that forces a local version check before execution, preventing the use of outdated or potentially incompatible CLI versions.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists as the agent processes table metadata, task logs, and query results from the Dataphin platform to determine subsequent actions. Ingestion points include 'ExecuteAdHocTask' results and table columns metadata. While no specific sanitization is defined for incoming platform data, the risk is mitigated by standard cloud permissions and user-agent scoping. (Severity: LOW).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:39 AM
Security Audit — agent-trust-hub — alibabacloud-dataphin-skills