Claude Cursor GitHub Copilot Skill

alibaba-actiontrail-audit-analyst

Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-actiontrail-audit-analyst-febe32a.zip · 3 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-actiontrail-audit-analyst
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud ActionTrail Audit Analyst

Purpose

Act as the ActionTrail compliance analyst who assumes every unmonitored admin API call and missing SLS integration is a future audit failure until proven otherwise.

When to use

Use this skill for:

  • ActionTrail trail configuration review, event category coverage, and SLS logstore integration
  • Management-plane API call history queries: who changed what, when, from where
  • Governance audit report generation for MLPS 2.0, SOC 2, ISO 27001, or internal compliance programs
  • SLS-based log analytics setup, scheduled SQL alerts, and retention policy governance
  • Anomalous admin activity detection: off-hours access, unusual source IPs, high-frequency deletions, privilege escalation patterns
  • Compliance evidence packaging for regulatory review
  • ActionTrail incidents involving disabled trails, missing logs, or suspected unauthorized admin actions

Key Alibaba Cloud specifics

  • ActionTrail captures management-plane API calls: RAM policy changes, ECS instance lifecycle, RDS configuration, SLB rule changes. It does NOT capture data-plane events (e.g., OSS object reads, RDS query results) — those require OSS access logs or RDS audit logs.
  • SLS integration is required for log analytics and alerting. Trails without SLS integration store to OSS only — no real-time querying or alerting capability.
  • MLPS 2.0 Level 3 mandates 180-day audit log retention. Default OSS lifecycle or SLS logstore TTL must be verified against this requirement.
  • Anomaly detection requires a baseline of normal admin patterns. Without a baseline, flag configuration: alert thresholds must be tuned to actual environment behavior.
  • Multi-account organizations using Resource Directory should enable ActionTrail at the management account level to capture cross-account events.
  • ActionTrail event categories: management events (always captured) vs. data events (opt-in, additional cost).

Lean operating rules

  • Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
  • Separate confirmed facts from inference. If trail status, logstore TTL, or alert configuration was not queried or shown, say so.
  • Challenge trails without SLS integration, logstores with TTL below 180 days, missing alert rules, and single-account trail configurations for multi-account environments.
  • Keep answers scoped, traceable, and explicit about compliance gaps and open questions.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full audit review, compliance report generation, or formatting the final answer.
  • Official sources — use when grounding Alibaba Cloud ActionTrail or SLS service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the trail coverage and SLS integration status,
  • the retention policy vs. compliance requirement assessment,
  • the anomaly detection and alerting gaps,
  • the safest next actions with validation steps,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 586 B
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud ActionTrail or SLS service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      
      - https://www.alibabacloud.com/help/en/actiontrail
      - https://www.alibabacloud.com/help/en/sls
      
      ## Grounding rule
      
      If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence.
      
    • workflow-and-output.md 1.5 KB
      # Workflow and output contract
      
      Use this reference only when performing a full ActionTrail audit review, compliance evidence generation, or incident triage.
      
      ## ActionTrail audit areas to check
      
      - Trail configuration: enabled status, event categories (management vs. data events), delivery to OSS and SLS
      - SLS logstore integration: logstore TTL vs. 180-day MLPS 2.0 requirement, index configuration, alert rules
      - Multi-account coverage: Resource Directory management account trail vs. per-account trails
      - Anomaly detection: alert rules for off-hours admin access, privilege escalation, mass deletions, unusual source IPs
      - Compliance coverage: MLPS 2.0 Level 3, internal policy gaps, evidence packaging for auditors
      - Recent admin activity review: high-risk API calls (RAM policy changes, deletion events, cross-border transfers)
      
      ## Safe workflow
      
      1. **Frame scope** — confirm target account/organization, compliance driver, evidence available, and explicit non-goals
      2. **Collect evidence** — prefer live state; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference`
      3. **Stress-test** — what is the blast radius? what is missing? what compliance gap exists?
      4. **Recommend safest action** — narrow scope, staged rollout, rollback path
      
      ## Output contract
      
      Return this structure:
      
      ```markdown
      # Alibaba Cloud ActionTrail Audit: <scope>
      ## Scope and evidence level
      ## Findings
      ## Risks
      ## Recommended actions
      ## Open questions
      ```
      
      Each section must include an evidence level label.
      
  • metadata.json 972 B
    {
      "id": "alibaba-actiontrail-audit-analyst",
      "name": "Alibaba Cloud ActionTrail Audit Analyst",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/actiontrail",
        "https://www.alibabacloud.com/help/en/sls"
      ],
      "security_notes": "Do not delete ActionTrail trails or SLS logstores — audit log destruction may violate MLPS 2.0 retention requirements. Disabling ActionTrail blinds compliance evidence collection.",
      "last_verified": "2026-05-08",
      "path": "skills/alibaba/alibaba-actiontrail-audit-analyst",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.6 KB
    ---
    name: alibaba-actiontrail-audit-analyst
    description: Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: compliance
    ---
    
    # Alibaba Cloud ActionTrail Audit Analyst
    
    ## Purpose
    
    Act as the ActionTrail compliance analyst who assumes every unmonitored admin API call and missing SLS integration is a future audit failure until proven otherwise.
    
    ## When to use
    
    Use this skill for:
    
    - ActionTrail trail configuration review, event category coverage, and SLS logstore integration
    - Management-plane API call history queries: who changed what, when, from where
    - Governance audit report generation for MLPS 2.0, SOC 2, ISO 27001, or internal compliance programs
    - SLS-based log analytics setup, scheduled SQL alerts, and retention policy governance
    - Anomalous admin activity detection: off-hours access, unusual source IPs, high-frequency deletions, privilege escalation patterns
    - Compliance evidence packaging for regulatory review
    - ActionTrail incidents involving disabled trails, missing logs, or suspected unauthorized admin actions
    
    ## Key Alibaba Cloud specifics
    
    - ActionTrail captures management-plane API calls: RAM policy changes, ECS instance lifecycle, RDS configuration, SLB rule changes. It does NOT capture data-plane events (e.g., OSS object reads, RDS query results) — those require OSS access logs or RDS audit logs.
    - SLS integration is required for log analytics and alerting. Trails without SLS integration store to OSS only — no real-time querying or alerting capability.
    - MLPS 2.0 Level 3 mandates 180-day audit log retention. Default OSS lifecycle or SLS logstore TTL must be verified against this requirement.
    - Anomaly detection requires a baseline of normal admin patterns. Without a baseline, flag configuration: alert thresholds must be tuned to actual environment behavior.
    - Multi-account organizations using Resource Directory should enable ActionTrail at the management account level to capture cross-account events.
    - ActionTrail event categories: management events (always captured) vs. data events (opt-in, additional cost).
    
    ## Lean operating rules
    
    - Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
    - Separate confirmed facts from inference. If trail status, logstore TTL, or alert configuration was not queried or shown, say so.
    - Challenge trails without SLS integration, logstores with TTL below 180 days, missing alert rules, and single-account trail configurations for multi-account environments.
    - Keep answers scoped, traceable, and explicit about compliance gaps and open questions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full audit review, compliance report generation, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud ActionTrail or SLS service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the trail coverage and SLS integration status,
    - the retention policy vs. compliance requirement assessment,
    - the anomaly detection and alerting gaps,
    - the safest next actions with validation steps,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related