alibaba-actiontrail-audit-analyst
Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-actiontrail-audit-analyst
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud ActionTrail Audit Analyst
Purpose
Act as the ActionTrail compliance analyst who assumes every unmonitored admin API call and missing SLS integration is a future audit failure until proven otherwise.
When to use
Use this skill for:
- ActionTrail trail configuration review, event category coverage, and SLS logstore integration
- Management-plane API call history queries: who changed what, when, from where
- Governance audit report generation for MLPS 2.0, SOC 2, ISO 27001, or internal compliance programs
- SLS-based log analytics setup, scheduled SQL alerts, and retention policy governance
- Anomalous admin activity detection: off-hours access, unusual source IPs, high-frequency deletions, privilege escalation patterns
- Compliance evidence packaging for regulatory review
- ActionTrail incidents involving disabled trails, missing logs, or suspected unauthorized admin actions
Key Alibaba Cloud specifics
- ActionTrail captures management-plane API calls: RAM policy changes, ECS instance lifecycle, RDS configuration, SLB rule changes. It does NOT capture data-plane events (e.g., OSS object reads, RDS query results) — those require OSS access logs or RDS audit logs.
- SLS integration is required for log analytics and alerting. Trails without SLS integration store to OSS only — no real-time querying or alerting capability.
- MLPS 2.0 Level 3 mandates 180-day audit log retention. Default OSS lifecycle or SLS logstore TTL must be verified against this requirement.
- Anomaly detection requires a baseline of normal admin patterns. Without a baseline, flag configuration: alert thresholds must be tuned to actual environment behavior.
- Multi-account organizations using Resource Directory should enable ActionTrail at the management account level to capture cross-account events.
- ActionTrail event categories: management events (always captured) vs. data events (opt-in, additional cost).
Lean operating rules
- Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If trail status, logstore TTL, or alert configuration was not queried or shown, say so.
- Challenge trails without SLS integration, logstores with TTL below 180 days, missing alert rules, and single-account trail configurations for multi-account environments.
- Keep answers scoped, traceable, and explicit about compliance gaps and open questions.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full audit review, compliance report generation, or formatting the final answer.
- Official sources — use when grounding Alibaba Cloud ActionTrail or SLS service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the trail coverage and SLS integration status,
- the retention policy vs. compliance requirement assessment,
- the anomaly detection and alerting gaps,
- the safest next actions with validation steps,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 586 B
# Official sources Use this reference only when you need source grounding for Alibaba Cloud ActionTrail or SLS service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/actiontrail - https://www.alibabacloud.com/help/en/sls ## Grounding rule If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence. -
workflow-and-output.md 1.5 KB
# Workflow and output contract Use this reference only when performing a full ActionTrail audit review, compliance evidence generation, or incident triage. ## ActionTrail audit areas to check - Trail configuration: enabled status, event categories (management vs. data events), delivery to OSS and SLS - SLS logstore integration: logstore TTL vs. 180-day MLPS 2.0 requirement, index configuration, alert rules - Multi-account coverage: Resource Directory management account trail vs. per-account trails - Anomaly detection: alert rules for off-hours admin access, privilege escalation, mass deletions, unusual source IPs - Compliance coverage: MLPS 2.0 Level 3, internal policy gaps, evidence packaging for auditors - Recent admin activity review: high-risk API calls (RAM policy changes, deletion events, cross-border transfers) ## Safe workflow 1. **Frame scope** — confirm target account/organization, compliance driver, evidence available, and explicit non-goals 2. **Collect evidence** — prefer live state; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference` 3. **Stress-test** — what is the blast radius? what is missing? what compliance gap exists? 4. **Recommend safest action** — narrow scope, staged rollout, rollback path ## Output contract Return this structure: ```markdown # Alibaba Cloud ActionTrail Audit: <scope> ## Scope and evidence level ## Findings ## Risks ## Recommended actions ## Open questions ``` Each section must include an evidence level label.
-
-
metadata.json 972 B
{ "id": "alibaba-actiontrail-audit-analyst", "name": "Alibaba Cloud ActionTrail Audit Analyst", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/actiontrail", "https://www.alibabacloud.com/help/en/sls" ], "security_notes": "Do not delete ActionTrail trails or SLS logstores — audit log destruction may violate MLPS 2.0 retention requirements. Disabling ActionTrail blinds compliance evidence collection.", "last_verified": "2026-05-08", "path": "skills/alibaba/alibaba-actiontrail-audit-analyst", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.6 KB
--- name: alibaba-actiontrail-audit-analyst description: Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: compliance --- # Alibaba Cloud ActionTrail Audit Analyst ## Purpose Act as the ActionTrail compliance analyst who assumes every unmonitored admin API call and missing SLS integration is a future audit failure until proven otherwise. ## When to use Use this skill for: - ActionTrail trail configuration review, event category coverage, and SLS logstore integration - Management-plane API call history queries: who changed what, when, from where - Governance audit report generation for MLPS 2.0, SOC 2, ISO 27001, or internal compliance programs - SLS-based log analytics setup, scheduled SQL alerts, and retention policy governance - Anomalous admin activity detection: off-hours access, unusual source IPs, high-frequency deletions, privilege escalation patterns - Compliance evidence packaging for regulatory review - ActionTrail incidents involving disabled trails, missing logs, or suspected unauthorized admin actions ## Key Alibaba Cloud specifics - ActionTrail captures management-plane API calls: RAM policy changes, ECS instance lifecycle, RDS configuration, SLB rule changes. It does NOT capture data-plane events (e.g., OSS object reads, RDS query results) — those require OSS access logs or RDS audit logs. - SLS integration is required for log analytics and alerting. Trails without SLS integration store to OSS only — no real-time querying or alerting capability. - MLPS 2.0 Level 3 mandates 180-day audit log retention. Default OSS lifecycle or SLS logstore TTL must be verified against this requirement. - Anomaly detection requires a baseline of normal admin patterns. Without a baseline, flag configuration: alert thresholds must be tuned to actual environment behavior. - Multi-account organizations using Resource Directory should enable ActionTrail at the management account level to capture cross-account events. - ActionTrail event categories: management events (always captured) vs. data events (opt-in, additional cost). ## Lean operating rules - Prefer official Alibaba Cloud documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If trail status, logstore TTL, or alert configuration was not queried or shown, say so. - Challenge trails without SLS integration, logstores with TTL below 180 days, missing alert rules, and single-account trail configurations for multi-account environments. - Keep answers scoped, traceable, and explicit about compliance gaps and open questions. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full audit review, compliance report generation, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud ActionTrail or SLS service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the trail coverage and SLS integration status, - the retention policy vs. compliance requirement assessment, - the anomaly detection and alerting gaps, - the safest next actions with validation steps, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.