alibabacloud-dataphin-skills

Warn

Audited by Socket on Aug 7, 2026

4 alerts found:

Anomalyx4
AnomalyLOW
references/assets/manage-asset-attributes/SKILL.md

The skill’s core behavior is coherent with its Dataphin asset-attribute management purpose, and its primary API/data flow targets official Alibaba infrastructure. The main security issues are install-trust expansion from forced auto-plugin-install/update and, more seriously, the SDK fallback’s `ignore_ssl = True`, which can expose credentials and traffic to interception. Overall this is better classified as suspicious/vulnerable rather than malicious.

Confidence: 89%Severity: 62%
AnomalyLOW
references/cli-installation-guide.md

No direct evidence of embedded malware in the provided text (it is installation guidance), but it contains meaningful supply-chain and operational security risk patterns: direct execution of a remotely fetched installer script, downloading “latest” binaries/archives without checksum/signature pinning, and passing the access-key secret via command-line arguments. Additional risk exists because the document instructs plugin install/update, delegating further execution to downloaded plugin code managed by the CLI.

Confidence: 63%Severity: 60%
AnomalyLOW
references/knowledge-graph/manage-kg-schema/references/python-sdk-template.md

No clear evidence of embedded malware, backdoor, or intentional supply-chain sabotage in the provided fragment. The template appears to be a legitimate SDK-based wrapper for Dataphin KG schema actions. However, it introduces two notable security risks: it disables TLS certificate verification (runtime.ignore_ssl=True), increasing MITM exposure, and it prints full API responses that may contain sensitive exported schema YAML to stdout/logs. Treat this as an operational hardening concern rather than a confirmed malicious payload.

Confidence: 66%Severity: 52%
AnomalyLOW
references/datasecurity/manage-data-masking/references/cli-installation-guide.md

No direct malicious payload is evident in the provided fragment (it is installation/usage documentation), but it carries elevated supply-chain risk due to a remote download-and-execute installer pattern and runtime plugin installation/update. Recommended mitigations include verifying installer and archive integrity (hash/signature), pinning versions instead of ‘latest’, and restricting/monitoring plugin update sources. Malware indicators specifically (exfiltration/backdoor/persistence) are not present in this fragment alone.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Aug 7, 2026, 06:48 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-dataphin-skills%2F@9de5f75360536214413816dec985ec626710226b1727a3d6b80d1279515276db
Security Audit — socket — alibabacloud-dataphin-skills