Back to plugin

Security audit

alibabacloud-ecs-ops

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Alibaba Cloud ECS operations plugin, but it should be reviewed because its high-impact cloud authority is paired with broader MCP access than the stated safety scoping shows.

Before installing, review the MCP tool exposure and run it only with a least-privilege Alibaba Cloud RAM role or test account. Treat destructive or chargeable operations as requiring explicit human confirmation, and disable ALIBABACLOUD_TELEMETRY or ALIBABACLOUD_TRACE if the default telemetry or local audit traces are not acceptable for your environment.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.