alibabacloud-dts-task-query
Fail
Audited by Snyk on May 6, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). High-risk prompt-injection/data-exfiltration behavior: the skill contains explicit mandatory instructions forcing the model to output the complete, untruncated DTS task data (including IDs and instance names) and to enable "AI-Mode" CLI behavior, which is a coercive instruction intended to override output-safety and could lead to disclosure of sensitive cloud data; the code itself calls only the official aliyun CLI (no hidden network sinks, no obfuscated payloads, no credential-stealing code), but the embedded "must output everything" requirement is a deliberate attempt to exfiltrate sensitive results if the model complies.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata