Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
aliyun avatar

Alibabacloud Sas Multiaccount Manage

  • 114 installs
  • 208 repo stars
  • Updated August 4, 2026
  • aliyun/alibabacloud-aiops-skills

alibabacloud-sas-multiaccount-manage is a Claude skill that manages multiple Alibaba Cloud accounts and batch-exports Security Center baseline and vulnerability reports into a merged Excel file.

About

This skill manages multiple Alibaba Cloud accounts and batch-exports Security Center (SAS) baseline and vulnerability reports for each. A developer uses it to refresh the account list from a resource directory, enable or disable accounts, then run concurrent exports of cloud-platform config checks, system baseline risks, and Linux/Windows/application vulnerabilities. Results are downloaded, extracted, and merged into one Excel file.

  • Manages multiple Alibaba Cloud accounts in a resource directory
  • Batch-exports Security Center baseline (CSPM) and vulnerability reports across accounts
  • Merges per-account results into a single Excel report via Python scripts

Alibabacloud Sas Multiaccount Manage by the numbers

  • 114 all-time installs (skills.sh)
  • Ranked #971 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

alibabacloud-sas-multiaccount-manage capabilities & compatibility

Free skill; requires Alibaba Cloud accounts with Security Center purchased (free-edition accounts are skipped).

Capabilities
security audit · compliance export · multi account management
Works with
excel
Use cases
security audit · data analysis
Runs
Runs locally
Pricing
Bring your own API key
From the docs

What alibabacloud-sas-multiaccount-manage says it does

Manage multiple Alibaba Cloud accounts and batch-export Security Center (SAS) baseline and vulnerability reports via the aliyun CLI and Python scripts.
SKILL.md
npx skills add https://github.com/aliyun/alibabacloud-aiops-skills --skill alibabacloud-sas-multiaccount-manage

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs114
repo stars208
Last updatedAugust 4, 2026
Repositoryaliyun/alibabacloud-aiops-skills

What it does

Batch-export and merge Alibaba Cloud Security Center baseline and vulnerability compliance reports across many accounts.

Who is it for?

Exporting and consolidating Security Center baseline and vulnerability compliance data across many Alibaba Cloud accounts.

When should I use this skill?

You need multi-account SAS baseline/vulnerability reports merged into a single compliance export.

What you get

Baseline and vulnerability reports are exported for all enabled accounts and merged into one Excel file with an account column.

By the numbers

  • Concurrent export capped at QPS <= 5

Files

SKILL.mdMarkdownGitHub ↗

Alibaba Cloud Security Center Multi-Account Management and Baseline Report Export

Use aliyun CLI and Python scripts to manage multiple Alibaba Cloud accounts in a resource directory and batch-export Security Center baseline reports for each account.

Prerequisites and Environment Setup

1. Install Alibaba Cloud CLI

# macOS
brew install aliyun-cli

# Or download from GitHub: https://github.com/aliyun/aliyun-cli/releases

Check credentials:

aliyun sts get-caller-identity

If the call fails, instruct the user to run aliyun configure and set up credentials (interactive step, must be completed by the user).

1.1 Configure AI mode and plugin mode (required)

This skill requires aliyun CLI plugin mode commands (kebab-case) and a fixed User-Agent declaration.

# Keep plugins up to date
aliyun plugin update

# Install required product plugins if missing
aliyun plugin install --names aliyun-cli-sts,aliyun-cli-sas

# Enable AI mode and set required UA segment
aliyun configure ai-mode enable
aliyun configure ai-mode set-user-agent --user-agent AlibabaCloud-Agent-Skills

# Optional checks / rollback
aliyun configure ai-mode show
aliyun configure ai-mode disable

2. Install Python ≥ 3.6

# Check version
python3 --version  # Requires 3.6+, 3.9+ recommended

3. Create Virtual Environment and Install Dependencies

Create a virtual environment in <skill-path>/scripts/ and install dependencies declared in pyproject.toml:

cd scripts/

# Option A: use venv
python3 -m venv .venv
.venv/bin/pip install -e .

# Option B: use uv (optional)
uv sync

# Option C: if current Python version is unsupported, install as system dependencies
pip install -r requirements.txt

4. Run Commands

All scripts must be executed with Python from the virtual environment (whether created via venv, uv, conda, etc.). This document uses .venv/bin/python in examples; replace it with your actual virtual environment path.

---

Working Directory

accounts.json and exported Excel files are saved in the agent's current working directory (the directory where the command is executed). Script files themselves are located in <skill-path>/scripts/. Do not switch into the scripts directory when running commands, or accounts.json location may shift unexpectedly.

# Example: run from any directory
.venv/bin/python /path/to/scripts/accounts.py refresh

Feature 1: Account Management (accounts.py)

Workflow

1. First use: run refresh to fetch account list from the resource directory. 2. Filter as needed: use search to find target accounts and get AccountId. 3. Enable/disable control: use enable / disable to decide which accounts participate in batch export.

Quick Start

Refresh account list

Fetch the latest account list from Alibaba Cloud resource directory and write to accounts.json. Existing enable states are preserved; new accounts are enabled by default.

.venv/bin/python accounts.py refresh
List all accounts
.venv/bin/python accounts.py list

Sample output:

1225574417218097    cwx                     [enabled]
1234567890123456    prod-account            [disabled]
Search accounts

Fuzzy-search by DisplayName, returning AccountId and enable status.

.venv/bin/python accounts.py search cwx
.venv/bin/python accounts.py search prod
Enable / disable accounts

Control whether an account participates in subsequent batch exports.

.venv/bin/python accounts.py enable 1225574417218097
.venv/bin/python accounts.py disable 1234567890123456

accounts.json Structure

[
  {
    "AccountId": "1225574417218097",
    "DisplayName": "cwx",
    "FolderId": "r-1Q4pqB",
    "IsMaAccount": "NO",
    "SasVersion": "0",
    "enable": true
  }
]

---

Feature 2: Batch Baseline Export (baseline.py)

Launch export tasks concurrently for all accounts with enable=true. After polling completion, files are downloaded, extracted, and merged into a single Excel file.

Workflow

1. Concurrent submission: submit export-record requests for all enabled accounts (QPS ≤ 5). 2. Concurrent polling: poll describe-export-info for each account until export completes. 3. Download and extract: download zip and extract xlsx. 4. Merge output: merge all account xlsx files into one file via merge.py, appending a “Resource Directory Account” column. 5. Cleanup temporary files: delete per-account temporary xlsx files after merge.

Prerequisites

  • accounts.py refresh has been executed and account enable/disable configuration is complete.
  • aliyun CLI is configured with valid credentials and has SAS export-record and describe-export-info permissions.
  • Accounts must have Security Center purchased (free edition accounts are skipped automatically).

Export cloud platform configuration check results (CSPM)

Export baselineCspm results for all enabled accounts and merge into baseline-cspm-merged-{date}.xlsx.

# Export for all enabled accounts
.venv/bin/python baseline.py export-cspm

# Export for one specific account
.venv/bin/python baseline.py export-cspm --account-id 1225574417218097

Export system baseline risk list

Export exportHcWarning risk list (high/medium/low, all statuses) for all enabled accounts and merge into system-warning-merged-{date}.xlsx.

# Export for all enabled accounts
.venv/bin/python baseline.py export-system-warning

# Export for one specific account
.venv/bin/python baseline.py export-system-warning --account-id 1225574417218097

Output Files

FileDescription
baseline-cspm-merged-{date}.xlsxMerged cloud platform configuration check results, including “Resource Directory Account” column
system-warning-merged-{date}.xlsxMerged system baseline risk list, including “Resource Directory Account” column

Error Handling

ScenarioBehavior
FreeVersionNotPermitSilently skip this account and continue others
NoPermission / ForbiddenSilently skip this account
Export failed (server-side error)Print [failed] message and continue with other accounts
All accounts skippedPrint message and exit without output file

---

Feature 3: Batch Vulnerability Export (vuln.py)

Launch vulnerability export tasks concurrently for all accounts with enable=true. Supports four vulnerability types. After polling completion, files are downloaded, extracted, and merged automatically.

Workflow

1. Concurrent submission: submit export-vul --force requests for all enabled accounts (QPS ≤ 5). 2. Concurrent polling: poll describe-vul-export-info --force for each account until export completes. 3. Download and extract: download zip and extract xlsx. 4. Merge output: merge all account xlsx files into one file via merge.py, appending a “Resource Directory Account” column. 5. Cleanup temporary files: delete per-account temporary xlsx files after merge.

When the current account is the same as the caller's primary account, --ResourceDirectoryAccountId is omitted automatically.

Prerequisites

  • accounts.py refresh has been executed and account enable/disable configuration is complete.
  • aliyun CLI is configured with valid credentials and has SAS export-vul and describe-vul-export-info permissions.
  • Accounts must have Security Center purchased (free edition accounts are skipped automatically).

Export Linux software vulnerabilities (CVE)

Export unresolved Linux software vulnerabilities (high/medium/low priority) for all enabled accounts and merge into vul-cve-merged-{date}.xlsx.

# Export for all enabled accounts
.venv/bin/python vuln.py export-cve

# Export for one specific account
.venv/bin/python vuln.py export-cve --account-id 1225574417218097

Export Windows system vulnerabilities

Export unresolved Windows system vulnerabilities (high/medium/low priority) for all enabled accounts and merge into vul-sys-merged-{date}.xlsx.

.venv/bin/python vuln.py export-sys
.venv/bin/python vuln.py export-sys --account-id 1225574417218097

Export application vulnerabilities (including SCA)

Export unresolved application vulnerabilities (ECS + container, including software composition analysis) for all enabled accounts and merge into vul-app-merged-{date}.xlsx.

.venv/bin/python vuln.py export-app
.venv/bin/python vuln.py export-app --account-id 1225574417218097

Export emergency vulnerabilities

Export emergency vulnerabilities (at-risk status) for all enabled accounts and merge into vul-emg-merged-{date}.xlsx.

.venv/bin/python vuln.py export-emg
.venv/bin/python vuln.py export-emg --account-id 1225574417218097

Output Files

FileDescription
vul-cve-merged-{date}.xlsxMerged Linux software vulnerability list, including “Resource Directory Account” column
vul-sys-merged-{date}.xlsxMerged Windows system vulnerability list, including “Resource Directory Account” column
vul-app-merged-{date}.xlsxMerged application vulnerability list (including SCA), including “Resource Directory Account” column
vul-emg-merged-{date}.xlsxMerged emergency vulnerability list, including “Resource Directory Account” column

Export Parameter Details

Typeexport-vul parameters
export-cve--Type cve --Necessity asap,later,nntf --Dealed n
export-sys--Type sys --Necessity asap,later,nntf --Dealed n
export-app--Type app --Necessity asap,later,nntf --AttachTypes sca --AssetType ECS,CONTAINER --Dealed n
export-emg--Type emg --RiskStatus y --Dealed n

Error Handling

ScenarioBehavior
FreeVersionNotPermitSilently skip this account and continue others
NoPermission / ForbiddenSilently skip this account
Export failed (server-side error)Print [failed] message and continue with other accounts
All accounts skippedPrint message and exit without output file

---

Notes

  • Scripts must run in a virtual environment. Examples use .venv/bin/python; replace with your actual virtual environment path.
  • Manage aliyun CLI credentials with aliyun configure; do not hardcode AK/SK.
  • SAS API supports only two endpoints: cn-shanghai (China mainland) and ap-southeast-1 (outside China mainland).

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.