alibabacloud-openclaw-ecs-dingtalk

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill executes remote scripts to set up the operating environment. This includes fetching a Node.js distribution script from a well-known service and an installation script from the vendor's own infrastructure on Alibaba Cloud OSS.
  • [COMMAND_EXECUTION]: Extensively uses the official Alibaba Cloud CLI and Cloud Assistant to manage cloud infrastructure and run shell commands on virtual instances.
  • [DATA_EXFILTRATION]: The skill manages sensitive credentials such as the Bailian API Key and DingTalk app secrets. It implements base64 encoding to prevent these secrets from appearing in clear text within execution logs and ensures communication occurs with authorized vendor endpoints.
  • [PROMPT_INJECTION]: Includes specific logic for validating user-provided parameters to reject shell special characters, effectively mitigating the risk of command injection during the automated deployment process.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 12:42 PM