alibabacloud-sre-toolkit

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces a strict read-only policy for all cloud operations, explicitly forbidding write actions such as Create, Delete, or Update via the aliyun CLI during diagnostics.\n- [SAFE]: Credential management is handled through the official Alibaba Cloud CLI. Instructions specifically prohibit echoing or storing AccessKeys/SecretKeys in plain text or project configuration files.\n- [SAFE]: Network communication is restricted to authenticated *.aliyuncs.com endpoints using the ACS3-HMAC-SHA256 signing algorithm, preventing data exfiltration to unauthorized hosts.\n- [SAFE]: Python dependencies in scripts/requirements.txt are pinned to specific versions and include SHA256 hashes to ensure supply chain integrity.\n- [SAFE]: The skill includes automated masking and redaction of credentials in generated diagnostic and inspection reports to prevent accidental data exposure.\n- [SAFE]: Subprocess executions and dynamic imports in session_manager.py and starops_manager.py are used for legitimate operational tasks, such as environment verification and CLI interaction, and do not present a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 02:30 AM
Security Audit — agent-trust-hub — alibabacloud-sre-toolkit