Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
cinience avatar

Alicloud Security Center Sas Test

  • 293 installs
  • 396 repo stars
  • Updated July 18, 2026
  • cinience/alicloud-skills

alicloud-security-center-sas-test is an agent skill that runs Alibaba Cloud Security Center (SAS) checks for developers who need vulnerability and compliance gaps surfaced before release approval.

About

alicloud-security-center-sas-test is a Security skill in cinience/alicloud-skills for running Security Center (SAS) validation on Alibaba Cloud workloads before release. The workflow executes SAS checks to surface open vulnerabilities, resource misconfigurations, and compliance gaps that would block production approval. Developers reach for this skill during pre-release security gates on ECS, ACK, or other Alibaba Cloud-hosted services. Tests assume Security Center is enabled and the target account or resource group is in scope. Catalog data shows 293 installs. Use it when a release checklist requires documented SAS findings rather than ad-hoc console review.

  • Security Center (SAS) test flows
  • Vulnerability and misconfiguration scans
  • Compliance posture checks
  • Pre-release remediation guidance
  • Cloud workload security validation

Alicloud Security Center Sas Test by the numbers

  • 293 all-time installs (skills.sh)
  • Ranked #641 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cinience/alicloud-skills --skill alicloud-security-center-sas-test

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs293
repo stars396
Last updatedJuly 18, 2026
Repositorycinience/alicloud-skills

How do you run Alibaba Cloud Security Center checks?

Run Security Center (SAS) checks and tests on Alibaba Cloud workloads to surface vulnerabilities, misconfigurations, and compliance gaps before release approval.

Who is it for?

DevOps and platform engineers gating Alibaba Cloud releases with Security Center vulnerability and compliance scans.

Skip if: Teams on non-Alibaba clouds or developers performing local application SAST without cloud Security Center access.

When should I use this skill?

User needs Security Center SAS checks, pre-release vulnerability scans, or compliance gap review on Alibaba Cloud workloads.

What you get

SAS vulnerability findings, misconfiguration report, and compliance gap summary for targeted cloud workloads.

  • Vulnerability findings report
  • Compliance gap summary

By the numbers

  • 293 catalog installs in Skillselion
  • Checks 3 Security Center dimensions: vulnerabilities, misconfigurations, and compliance gaps

Files

SKILL.mdMarkdownGitHub ↗

Category: service

Cloud Backup

Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for Cloud Backup.

Workflow

1) Confirm region, resource identifiers, and desired action. 2) Discover API list and required parameters (see references). 3) Call API with SDK or OpenAPI Explorer. 4) Verify results with describe/list APIs.

AccessKey priority (must follow)

1) Environment variables: ALIBABACLOUD_ACCESS_KEY_ID / ALIBABACLOUD_ACCESS_KEY_SECRET / ALIBABACLOUD_REGION_ID Region policy: ALIBABACLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. 2) Shared config file: ~/.alibabacloud/credentials

API discovery

  • Product code: hbr
  • Default API version: 2017-09-08
  • Use OpenAPI metadata endpoints to list APIs and get schemas (see references).

High-frequency operation patterns

1) Inventory/list: prefer List* / Describe* APIs to get current resources. 2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations. 3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.

Minimal executable quickstart

Use metadata-first discovery before calling business APIs:

python scripts/list_openapi_meta_apis.py

Optional overrides:

python scripts/list_openapi_meta_apis.py --product-code <ProductCode> --version <Version>

The script writes API inventory artifacts under the skill output directory.

Output policy

If you need to save responses or generated artifacts, write them under: output/aliyun-hbr-backup/

Validation

mkdir -p output/aliyun-hbr-backup
for f in skills/backup/aliyun-hbr-backup/scripts/*.py; do
  python3 -m py_compile "$f"
done
echo "py_compile_ok" > output/aliyun-hbr-backup/validate.txt

Pass criteria: command exits 0 and output/aliyun-hbr-backup/validate.txt is generated.

Output And Evidence

  • Save artifacts, command outputs, and API response summaries under output/aliyun-hbr-backup/.
  • Include key parameters (region/resource id/time range) in evidence files for reproducibility.

Prerequisites

  • Configure least-privilege Alibaba Cloud credentials before execution.
  • Prefer environment variables: ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET, optional ALIBABACLOUD_REGION_ID.
  • If region is unclear, ask the user before running mutating operations.

References

  • Sources: references/sources.md

Related skills

How it compares

Pick this skill over firewall-only tests when the goal is Security Center vulnerability and compliance scanning across workloads, not network rule validation.

FAQ

What does alicloud-security-center-sas-test find?

alicloud-security-center-sas-test finds vulnerabilities, misconfigurations, and compliance gaps on Alibaba Cloud workloads through Security Center (SAS) checks. The skill supports pre-release approval when documented security findings must be reviewed before production deployment

When should teams run SAS tests on Alibaba Cloud?

Teams should run alicloud-security-center-sas-test before release approval when Security Center coverage is enabled on target accounts or resource groups. The skill fits pre-ship security gates rather than ongoing runtime incident response.

Securityauditappseccompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.