alibabacloud-sas-vul-repairAlicloud Service Scenario-Based Skill. Use for the vulnerability module of Alibaba Cloud Security Center (SAS): querying and filtering vulnerabilities (by severity/type/asset/status), triggering vulnerability repair and post-fix re-verification, interpreting repair failure error codes (8009, 8037, 9003, etc.) with repository and network troubleshooting, handling "fixed but still detected" status refresh, and manual repair guidance for non-standard systems (self-compiled kernels, non-Alibaba-Cloud hosts, offline environments, custom images, EOL systems). Triggers: "Security Center vulnerability", "vulnerability repair", "vulnerability fix", "fix failed", "repair failed", "vulnerability error code", "fixed but still detected", "re-verify vulnerability", "unfixed vulnerability list", "self-compiled kernel", "manual vulnerability fix", "CVE", "漏洞修复", "修复失败", "漏洞错误码", "已修复仍检出", "重新验证漏洞", "漏洞复检", "未修复漏洞清单", "yum 源超时", "自编译内核", "手动修复漏洞".
Install via ClawdBot CLI:
clawdbot install sdk-team/alibabacloud-sas-vul-repairGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval (Accesses system directories or attempts privilege escalation
sudo mvCalls external URL not in known-safe list
https://aliyuncli.alicdn.com/setup.shAudited Oct 7, 2026 · audit v1.0
Generated Oct 7, 2026
Security operations teams use this skill to query and filter vulnerabilities across hundreds of Alibaba Cloud ECS and hybrid hosts by severity, type, asset, and status. They then trigger bulk repairs via the SAS vulnerability module and re-verify fixes, closing the loop on CVE exposure within SLA windows.
When automated vulnerability fixes fail (e.g., error codes 8009, 8037, 9003), engineers use this skill to interpret error causes, diagnose yum repository timeouts or network issues, and apply targeted repository or connectivity fixes before retrying repair. It converts opaque failure codes into actionable remediation steps.
Organizations subject to regulatory frameworks (MLPS 2.0, ISO 27001, PCI DSS) leverage this skill to pull unfixed vulnerability lists, grouped statistics, and fix rates from Security Center for audit evidence. The re-verification and whitelist query capabilities support defensible remediation documentation.
Teams running self-compiled kernels, non-Alibaba Cloud hosts, offline environments, custom images, or EOL operating systems use the manual repair guidance to handle scenarios automation cannot cover. The skill provides adaptation strategies where standard agent-based repair is unavailable.
Security analysts investigate cases where a vulnerability appears resolved but continues to trigger alerts, using status refresh and re-verification flows to distinguish stale scan data, incomplete patches, or re-introduced CVEs. This reduces alert fatigue and prevents premature closure of remediation tickets.
Alibaba Cloud customers purchase Security Center editions (Basic, Advanced, Enterprise, Ultimate) with vulnerability management quotas, and this skill operationalizes the vulnerability module included in those subscriptions. Higher tiers unlock pay-as-you-go fix counts and auto-repair capabilities that drive upgrade revenue.
MSSPs and cloud MSPs deliver vulnerability remediation as a recurring service, using this skill to standardize triage, repair execution, and re-verification across client accounts. Labor is amortized through automation while SLAs on critical CVE remediation justify premium retainers.
Consultancies package this skill into assessment engagements that inventory unfixed CVEs, interpret complex failure codes, and design manual repair workflows for non-standard systems. Deliverables feed into broader compliance certifications and architecture reviews.
💬 Integration Tip
Ensure Aliyun CLI >= 3.3.3 is installed, auto-plugin-install and plugin update are enabled, and the CLI profile region points to the correct SAS site (cn-shanghai or ap-southeast-1) for International accounts. Grant the listed yundun-sas:*/yundun-aegis:* RAM actions and verify credentials via `aliyun configure list` without ever echoing AK/SK values.
Scored Oct 7, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...