
Alicloud Security Cloudfw Test
- 293 installs
- 396 repo stars
- Updated July 18, 2026
- cinience/alicloud-skills
alicloud-security-cloudfw-test is an agent skill that validates Alibaba Cloud firewall rules, policies, and traffic controls for developers who need misconfiguration and exposure risks caught before release.
About
alicloud-security-cloudfw-test is a Security skill in cinience/alicloud-skills for validating Alibaba Cloud firewall configuration before release or after network changes. The workflow reviews firewall rules, policies, and traffic controls to catch overly permissive rules, conflicting policies, and exposure paths that would leave workloads reachable from unintended networks. Developers reach for this skill after VPC or security-group edits and before approving a deployment that depends on strict ingress and egress boundaries. Tests assume Cloud Firewall or equivalent Alibaba Cloud network security services are in scope for the target environment. Catalog data shows 293 installs. Use it when a network change requires documented firewall validation rather than manual console spot checks.
- Cloud firewall policy review
- Rule coverage and gap analysis
- Controlled traffic validation
- Misconfiguration detection patterns
- Pre-release security sign-off checks
Alicloud Security Cloudfw Test by the numbers
- 293 all-time installs (skills.sh)
- Ranked #641 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cinience/alicloud-skills --skill alicloud-security-cloudfw-testAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 293 |
|---|---|
| repo stars | ★ 396 |
| Last updated | July 18, 2026 |
| Repository | cinience/alicloud-skills ↗ |
How do you test Alibaba Cloud firewall rules?
Validate Alibaba Cloud firewall rules, policies, and traffic controls before release or after network changes to catch misconfigurations and exposure risks.
Who is it for?
Platform engineers validating Alibaba Cloud firewall posture after VPC edits or before network-dependent releases.
Skip if: Developers auditing application-layer OWASP issues or teams without Alibaba Cloud firewall services configured.
When should I use this skill?
User changed cloud firewall rules, needs pre-release network security validation, or wants exposure risk checks on Alibaba Cloud traffic controls.
What you get
Firewall rule audit results, policy conflict findings, and exposure risk report for targeted cloud networks.
- Firewall rule audit report
- Exposure risk findings
By the numbers
- 293 catalog installs in Skillselion
- Validates firewall rules, policies, and traffic controls in 3 network security areas
Files
Category: service
Cloud Backup
Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for Cloud Backup.
Workflow
1) Confirm region, resource identifiers, and desired action. 2) Discover API list and required parameters (see references). 3) Call API with SDK or OpenAPI Explorer. 4) Verify results with describe/list APIs.
AccessKey priority (must follow)
1) Environment variables: ALIBABACLOUD_ACCESS_KEY_ID / ALIBABACLOUD_ACCESS_KEY_SECRET / ALIBABACLOUD_REGION_ID Region policy: ALIBABACLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. 2) Shared config file: ~/.alibabacloud/credentials
API discovery
- Product code:
hbr - Default API version:
2017-09-08 - Use OpenAPI metadata endpoints to list APIs and get schemas (see references).
High-frequency operation patterns
1) Inventory/list: prefer List* / Describe* APIs to get current resources. 2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations. 3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.
Minimal executable quickstart
Use metadata-first discovery before calling business APIs:
python scripts/list_openapi_meta_apis.pyOptional overrides:
python scripts/list_openapi_meta_apis.py --product-code <ProductCode> --version <Version>The script writes API inventory artifacts under the skill output directory.
Output policy
If you need to save responses or generated artifacts, write them under: output/aliyun-hbr-backup/
Validation
mkdir -p output/aliyun-hbr-backup
for f in skills/backup/aliyun-hbr-backup/scripts/*.py; do
python3 -m py_compile "$f"
done
echo "py_compile_ok" > output/aliyun-hbr-backup/validate.txtPass criteria: command exits 0 and output/aliyun-hbr-backup/validate.txt is generated.
Output And Evidence
- Save artifacts, command outputs, and API response summaries under
output/aliyun-hbr-backup/. - Include key parameters (region/resource id/time range) in evidence files for reproducibility.
Prerequisites
- Configure least-privilege Alibaba Cloud credentials before execution.
- Prefer environment variables:
ALIBABACLOUD_ACCESS_KEY_ID,ALIBABACLOUD_ACCESS_KEY_SECRET, optionalALIBABACLOUD_REGION_ID. - If region is unclear, ask the user before running mutating operations.
References
- Sources:
references/sources.md
interface:
display_name: "Alibaba Cloud Backup HBR"
short_description: "Cloud Backup vault and job workflows"
default_prompt: "Use $aliyun-hbr-backup to complete this backup task on Alibaba Cloud."
Sources
- OpenAPI product page:
https://api.aliyun.com/product/hbr - API list (metadata):
https://api.aliyun.com/meta/v1/products/hbr/versions/2017-09-08/api-docs.json - API definition (single API):
https://api.aliyun.com/meta/v1/products/hbr/versions/2017-09-08/apis/{ApiName}/api.json
#!/usr/bin/env python3
"""Fetch OpenAPI metadata API list for one product/version and save to output/.
Env:
- OPENAPI_META_TIMEOUT (seconds, default: 20)
"""
from __future__ import annotations
import argparse
import json
import os
import pathlib
import urllib.request
DEFAULT_PRODUCT_CODE = "hbr"
DEFAULT_VERSION = "2017-09-08"
OUTPUT_DIR = pathlib.Path("output/aliyun-hbr-backup")
def fetch_json(url: str, timeout: int) -> dict:
req = urllib.request.Request(url, headers={"User-Agent": "codex-skill"})
with urllib.request.urlopen(req, timeout=timeout) as resp:
return json.loads(resp.read().decode("utf-8"))
def main() -> None:
parser = argparse.ArgumentParser()
parser.add_argument("--product-code", default=DEFAULT_PRODUCT_CODE)
parser.add_argument("--version", default=DEFAULT_VERSION)
parser.add_argument("--output-dir", default=str(OUTPUT_DIR))
args = parser.parse_args()
timeout = int(os.getenv("OPENAPI_META_TIMEOUT", "20"))
output_dir = pathlib.Path(args.output_dir)
output_dir.mkdir(parents=True, exist_ok=True)
url = (
f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
f"/versions/{args.version}/api-docs.json"
)
payload = fetch_json(url, timeout)
raw_apis = payload.get("apis", {})
if isinstance(raw_apis, dict):
api_names = sorted(raw_apis.keys())
elif isinstance(raw_apis, list):
names = []
for item in raw_apis:
if isinstance(item, dict):
name = item.get("name") or item.get("apiName")
if name:
names.append(name)
elif isinstance(item, str):
names.append(item)
api_names = sorted(set(names))
else:
api_names = []
json_file = output_dir / f"{args.product_code}_{args.version}_api_docs.json"
md_file = output_dir / f"{args.product_code}_{args.version}_api_list.md"
json_file.write_text(json.dumps(payload, ensure_ascii=False, indent=2), encoding="utf-8")
md_lines = [
f"# {args.product_code} {args.version} API List",
"",
f"- Source: {url}",
f"- API count: {len(api_names)}",
"",
]
md_lines.extend([f"- `{name}`" for name in api_names])
md_file.write_text("\n".join(md_lines) + "\n", encoding="utf-8")
print(f"Saved: {json_file}")
print(f"Saved: {md_file}")
if __name__ == "__main__":
main()
Related skills
How it compares
Pick this skill over Security Center SAS tests when the concern is firewall rules and network traffic exposure, not host-level vulnerability findings.
FAQ
What does alicloud-security-cloudfw-test validate?
alicloud-security-cloudfw-test validates Alibaba Cloud firewall rules, policies, and traffic controls to catch misconfigurations and exposure risks. The skill fits pre-release or post-change network security review when ingress and egress boundaries must be verified before deploy
When should teams run cloud firewall tests?
Teams should run alicloud-security-cloudfw-test before release or immediately after network or firewall policy changes on Alibaba Cloud. The skill targets exposure and misconfiguration risks that Security Center workload scans may not cover at the network rule level.