alibabacloud-waf-billing-backup

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill incorporates explicit security guidelines for the agent, such as strictly prohibiting the retrieval, echoing, or printing of AccessKey/SecretKey values and credential files. It also enforces the use of read-only APIs to prevent unauthorized modifications.
  • [COMMAND_EXECUTION]: The skill utilizes the aliyun-cli tool to interact with Alibaba Cloud services and uses standard system commands (date, mkdir, bash) for local file management and directory hierarchy creation for backups.
  • [EXTERNAL_DOWNLOADS]: Reference documentation includes links to download the official aliyun-cli from Alibaba Cloud's trusted CDN (aliyuncli.alicdn.com). These downloads are verified as part of the vendor's official toolchain.
  • [SAFE]: The skill implements session-based observability by requiring a unique session-id in the User-Agent header, which helps in auditing and tracking API calls without exposing sensitive user metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 02:36 AM
Security Audit — agent-trust-hub — alibabacloud-waf-billing-backup