alicloud-platform-aliyun-cli

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (providing a generic Alibaba Cloud CLI experience with install, configure, and API actions) aligns with the described capabilities. However, there are notable security concerns: the installation relies on an unverified direct URL download with no clear checksum/signature verification, and credentials are handled in ways that could lead to exposure through logs or evidentiary outputs. The data flows are largely legitimate for a CLI tool but require stronger supply-chain protections and explicit credential-handling mitigations (e.g., pinned official packages, checksum verification, least-privilege scopes, and careful log management). Given these factors, the skill is best classified as SUSPICIOUS with elevated attention to secure installation practices and credential handling, rather than BENIGN.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:27 AM
Package URL
pkg:socket/skills-sh/cinience%2Falicloud-skills%2Falicloud-platform-aliyun-cli%2F@b12e75f139e5bc092ce6742327436111ac6b4338