alicloud-network-dns-cli
Warn
Audited by Socket on Mar 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill concept—managing Alibaba Cloud DNS via aliyun-cli—is coherent with its described purpose. However, the installation approach relies on downloading an unverifiable binary from an external URL, which is a significant supply-chain and credential-risk concern. Credentials are handled via a CLI configuration step, which is appropriate but increases exposure surface if the environment is compromised. Overall, the footprint is suspicious to high for supply-chain risk and credential handling, and should be remediated by using trusted installation sources (official package registries or verified checksums) and by enforcing strict credential handling and audit logging.
Confidence: 98%Severity: 80%
Audit Metadata