alicloud-data-analytics-dataanalysisgbi

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches OpenAPI metadata (API definitions) from api.aliyun.com, which is the official domain for Alibaba Cloud's API Explorer and metadata service. These operations are neutral and follow official documentation for dynamic API discovery.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (scripts/list_openapi_meta_apis.py) to automate the retrieval of API schemas. This is a standard automation pattern for managing cloud resources.
  • [CREDENTIALS_UNSAFE]: The skill documentation correctly identifies that users should provide credentials via standard environment variables (ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET) or the official shared credentials file (~/.alibabacloud/credentials). It does not contain hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 10:14 AM