Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
cinience avatar

Alicloud Security Kms Test

  • 295 installs
  • 396 repo stars
  • Updated July 18, 2026
  • cinience/alicloud-skills

alicloud-security-kms-test is a Claude Code smoke-test skill that verifies Alibaba Cloud KMS keys, rotation, encryption contexts, and access policies for developers who need read-only KMS connectivity checks before produ

About

alicloud-security-kms-test is a minimal viable test skill in cinience/alicloud-skills that validates read-only connectivity to Alibaba Cloud Key Management Service before production secrets workflows. The test confirms OpenAPI metadata for KMS product code Kms at API version 2016-01-20, then executes one read-only query such as ListKeys and records request ID, return count, and error codes if permissions fail. Prerequisites include ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET, and ALICLOUD_REGION_ID. Pass means the read query succeeds or returns an explicit permission error developers can remediate. Developers reach for this test after configuring KMS credentials, before wiring encryption into apps, or when debugging key policy and rotation issues on regulated workloads.

  • KMS key and alias verification
  • Encrypt-decrypt round-trip tests
  • Rotation and lifecycle policy checks
  • IAM and grant access audits
  • Compliance-ready evidence capture

Alicloud Security Kms Test by the numbers

  • 295 all-time installs (skills.sh)
  • Ranked #640 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cinience/alicloud-skills --skill alicloud-security-kms-test

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs295
repo stars396
Last updatedJuly 18, 2026
Repositorycinience/alicloud-skills

How do you verify Alibaba Cloud KMS connectivity?

Verify Alibaba Cloud KMS keys, rotation, encryption contexts, and access policies before shipping features that depend on secrets or regulated data protection.

Who is it for?

Developers shipping features on Alibaba Cloud KMS who need a read-only smoke test confirming keys, policies, and API auth before encryption goes live.

Skip if: Teams on AWS KMS or HashiCorp Vault, or projects needing full key lifecycle automation rather than a minimal ListKeys connectivity check.

When should I use this skill?

KMS credentials are configured, an app will encrypt with Alibaba Cloud keys, or a developer needs to confirm ListKeys access before implementing secrets management.

What you get

KMS ListKeys response evidence, request ID log, key count or explicit permission error, and pass/fail test record.

  • ListKeys response evidence
  • Request ID log
  • Pass/fail connectivity report

By the numbers

  • Targets KMS OpenAPI product code Kms at default API version 2016-01-20

Files

SKILL.mdMarkdownGitHub ↗

Category: service

Cloud Backup

Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for Cloud Backup.

Workflow

1) Confirm region, resource identifiers, and desired action. 2) Discover API list and required parameters (see references). 3) Call API with SDK or OpenAPI Explorer. 4) Verify results with describe/list APIs.

AccessKey priority (must follow)

1) Environment variables: ALIBABACLOUD_ACCESS_KEY_ID / ALIBABACLOUD_ACCESS_KEY_SECRET / ALIBABACLOUD_REGION_ID Region policy: ALIBABACLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. 2) Shared config file: ~/.alibabacloud/credentials

API discovery

  • Product code: hbr
  • Default API version: 2017-09-08
  • Use OpenAPI metadata endpoints to list APIs and get schemas (see references).

High-frequency operation patterns

1) Inventory/list: prefer List* / Describe* APIs to get current resources. 2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations. 3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.

Minimal executable quickstart

Use metadata-first discovery before calling business APIs:

python scripts/list_openapi_meta_apis.py

Optional overrides:

python scripts/list_openapi_meta_apis.py --product-code <ProductCode> --version <Version>

The script writes API inventory artifacts under the skill output directory.

Output policy

If you need to save responses or generated artifacts, write them under: output/aliyun-hbr-backup/

Validation

mkdir -p output/aliyun-hbr-backup
for f in skills/backup/aliyun-hbr-backup/scripts/*.py; do
  python3 -m py_compile "$f"
done
echo "py_compile_ok" > output/aliyun-hbr-backup/validate.txt

Pass criteria: command exits 0 and output/aliyun-hbr-backup/validate.txt is generated.

Output And Evidence

  • Save artifacts, command outputs, and API response summaries under output/aliyun-hbr-backup/.
  • Include key parameters (region/resource id/time range) in evidence files for reproducibility.

Prerequisites

  • Configure least-privilege Alibaba Cloud credentials before execution.
  • Prefer environment variables: ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET, optional ALIBABACLOUD_REGION_ID.
  • If region is unclear, ask the user before running mutating operations.

References

  • Sources: references/sources.md

Related skills

FAQ

What API does alicloud-security-kms-test call?

alicloud-security-kms-test calls a read-only KMS API such as ListKeys on product code Kms at API version 2016-01-20. It records request ID, returned key count, or explicit permission error codes for troubleshooting.

What environment variables does the KMS test need?

alicloud-security-kms-test needs ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET, and ALICLOUD_REGION_ID configured. Read-only success or a clear permission error both count as valid smoke-test outcomes.

Securitysecretscompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.