alibabacloud-opc-advisor
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a read-only advisor. It does not access sensitive local files or credentials.
- [COMMAND_EXECUTION]: The skill documents legitimate use of the
aliyunCLI for fetching current pricing. These calls are configured with a unified User-Agent including a session ID for transparency and auditing. - [EXTERNAL_DOWNLOADS]: All external references and purchase links target official Alibaba Cloud domains (e.g.,
aliyun.com,opc.aliyun.com). These are trusted vendor resources. - [PROMPT_INJECTION]: The skill implements a robust state machine with mandatory interaction gates and branch routing, which effectively prevents typical prompt injection bypasses.
- [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill primarily generates text-based recommendations and structured YAML for downstream automation.
- [SAFE]: The skill includes extensive security guidance for users, such as a 38-item UGC hardening checklist, showing a strong focus on defensive best practices.
Audit Metadata