polardbx-ops

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the official Alibaba Cloud CLI installation script from a well-known service domain (aliyuncli.alicdn.com).
  • [COMMAND_EXECUTION]: Utilizes the aliyun CLI and bundled Bash scripts (poll_task.sh, spec_lookup.sh) to perform cloud management tasks and local hardware configuration lookups.
  • [PROMPT_INJECTION]: Ingests untrusted data via user prompt parameters (e.g., RegionId, DBInstanceName) which are interpolated into shell commands. While boundary markers are absent in the scripts, the skill mitigates the risk of indirect prompt injection by enforcing mandatory secondary confirmation for all billable, destructive, or security-sensitive operations. Capability inventory includes cloud API access and local shell execution; sanitization relies on instructions to avoid hardcoding secrets and to use placeholders for sensitive inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:07 AM
Security Audit — agent-trust-hub — polardbx-ops