alicloud-network-dns-cli

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill concept—managing Alibaba Cloud DNS via aliyun-cli—is coherent with its described purpose. However, the installation approach relies on downloading an unverifiable binary from an external URL, which is a significant supply-chain and credential-risk concern. Credentials are handled via a CLI configuration step, which is appropriate but increases exposure surface if the environment is compromised. Overall, the footprint is suspicious to high for supply-chain risk and credential handling, and should be remediated by using trusted installation sources (official package registries or verified checksums) and by enforcing strict credential handling and audit logging.

Confidence: 98%Severity: 80%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/cinience%2Falicloud-skills%2Falicloud-network-dns-cli%2F@0e73e23b16dc5d532d4fb8eed17598274b7ddc7b