alibabacloud-waf-report
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the official aliyun CLI to perform read-only data collection from WAF and SLS services. Instructions strictly prohibit write operations to production rules and require every command to be annotated with a specific session-based User-Agent for auditability.
- [EXTERNAL_DOWNLOADS]: Retrieves geographic and ASN metadata from the well-known service ipinfo.io. These outbound requests are used to enrich IP analysis and are constrained by short connection timeouts and user-agent tagging.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from security logs and user samples, which is a standard surface for monitoring tools.
- Ingestion points: Data is sourced from SLS traffic logs, WAF OpenAPI responses, and user-supplied offline samples.
- Boundary markers: The methodology requires the agent to explicitly distinguish between technical facts and unverified assumptions to mitigate manipulation.
- Capability inventory: Agent capabilities are limited to read-only CLI calls and network lookups for metadata; no shell-piped execution or dynamic code generation is present.
- Sanitization: Enforces a strict redaction policy for AccessKeys, tokens, cookies, and sensitive PII across all evidence items and generated reports.
Audit Metadata