alicloud-ai-chatbot
Fail
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill aligns with its stated purpose of managing Alibaba Cloud Beebot resources via OpenAPI/SDK and includes credential usage, API discovery, and result validation. Data flows from user input and credentials to authenticated API calls and local artifacts are coherent with the goal. Security concerns center on credential handling, local artifact storage, and ensuring strict TLS and endpoint trust. Overall risk is moderate due to credential access and data at rest in artifacts, but no obviously malicious behavior detected. Recommend tightening credential handling, adding explicit access controls for output artifacts, and ensuring dependency integrity for any Python tooling.
Confidence: 98%
Audit Metadata