alibabacloud-workbench-cli
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities fit its stated Alibaba ECS management purpose, and its network destinations appear vendor-aligned, but the trust model is weak: it installs and updates an external CLI through unpinned remote scripts from an OSS bucket without clearly verifiable public source/releases, then forwards cloud credentials to that binary. This is a coherent admin skill with significant supply-chain and credential-forwarding risk, not confirmed malware.
Confidence: 84%Severity: 84%
Audit Metadata