Real Skill packageSource verifiedClawHub registry

alibabacloud-agent-toolkit-install

Install Alibaba Cloud Agent Toolkit end-to-end: verify and set up prerequisites (uv, Alibaba Cloud CLI, authentication, CLI plugins, MCP Server Core, bearer token exchange), then install the toolkit via the current client's supported plugin mechanism. Use when: alibabacloud agent toolkit install, environment check, prerequisite check, setup alibabacloud, plugin install, toolkit setup, mcp core setup, aliyun CLI setup.

Identity and source

Publisher attributionalibabacloud-skills-teamregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 68% rule confidence
Package forminstruction bundle5 recorded files
Canonical sourceClawHub registryclawhub:sdk-team:alibabacloud-agent-toolkit-install
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/11/2026.claude/skills/alibabacloud-agent-toolkit-install

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/11/2026.agents/skills/alibabacloud-agent-toolkit-install

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/11/2026skills/alibabacloud-agent-toolkit-install

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @sdk-team/alibabacloud-agent-toolkit-install
clawhub inspect @sdk-team/alibabacloud-agent-toolkit-install --version 0.0.2

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
5 / 5 inspected as text
Checked
9/11/2026, 4:39:59 AM
Scanner
0.1.3
Policy
1.0.3
2 automated findings
highRemote content is piped directly to a shellSKILL.md:90 · confidence 98%curl -LsSf https://astral.sh/uv/install.sh \| sh
mediumRemote installer is downloaded without an integrity checkSKILL.md:38 · confidence 70%curl -fsSL https://aliyuncli.alicdn.com/setup.sh
1 High/Critical review queue entry
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
Open human review queue →
3 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem write — automatically inferred
5 dependency and API indicators
  • api: aliyuncli.alicdn.com
  • api: astral.sh
  • api: clawhub.ai
  • api: github.com
  • api: ram.console.aliyun.com
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/11/2026, 2:35:17 AM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:d1c44d8137a9b35357a071c6e16891d5d6004c5049c8fc2e19b998d05444076f
Show up to 5 recorded paths
  • references/manifest.json
  • references/ram-policies.md
  • scripts/install-aliyun-cli-windows.ps1
  • skill-card.md
  • SKILL.md

Source changelog

- Enforced strict user-agent versioning: all cloud API calls now read skill version from `references/manifest.json` and use a unique per-skill 32-digit session ID. No guessing or copying is allowed. - Added Windows installer script for CLI: included `scripts/install-aliyun-cli-windows.ps1`. - Updated install/check flows to require Aliyun CLI >= 3.3.3. - Introduced `references/ram-policies.md` and `references/manifest.json` for manifest-based configuration and permissions documentation. - Clarified local vs. cloud command usage: user-agent flags on cloud API calls only, never on utility commands. - Internal docs rearranged/removed: dropped obsolete `skill-card.md`.