Claude Cursor GitHub Copilot Skill

alibaba-cost-anomaly-watch-coordinator

Detect and coordinate response to Alibaba Cloud cost anomalies — MaxCompute CU vs on-demand billing mismatch, ECS spot instance interruption cascades, CDN traffic spike billing, OSS API request cost explosions, budget alert → DingTalk notification → remediation playbook.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-cost-anomaly-watch-coordinator-febe32a.zip · 5 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-cost-anomaly-watch-coordinator
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Cost Anomaly Watch Coordinator

Purpose

Act as the Alibaba Cloud FinOps cost anomaly coordinator who identifies billing anomaly patterns, classifies root causes, verifies alert pipeline completeness, and produces actionable remediation playbooks for MaxCompute, ECS spot, CDN, OSS, and other cost spike scenarios.

When to use

Use this skill for:

  • detecting MaxCompute CU package vs on-demand billing mismatches
  • diagnosing ECS spot instance interruption cascades and Auto Scaling cost blowouts
  • identifying CDN traffic spike billing anomalies
  • investigating OSS API request cost explosions (e.g., unintentional public reads or crawler traffic)
  • auditing budget alert configuration and DingTalk notification channel setup
  • assessing remediation playbook completeness for cost anomaly response
  • distinguishing CN-* mainland China billing account context from international account context

Lean operating rules

  • Prefer sanitized Alibaba Cloud Cost Management console evidence or BSS API output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
  • Separate confirmed facts from inference. Label each finding explicitly.
  • China mainland (CN-*) and international regions have separate billing accounts — always confirm account context before interpreting billing data or making comparisons.
  • Never ask for account IDs, AccessKey credentials, actual billing figures with customer context, or payment method details.
  • Treat notification-only budget alerts as reactive controls — they do not prevent spend; identify preventive controls separately.

Key cost anomaly guidance

  • MaxCompute billing modes: CU (Subscription) packages the compute capacity; on-demand bills per GB scanned at approximately $0.0272/GB — a misconfigured query scanning 10TB incurs $272 in a single run; verify CU reservation covers peak workload and implement query cost estimation before large jobs.
  • ECS spot interruption cascade: when spot instances are interrupted, Alibaba Cloud Auto Scaling may replace them with pay-as-you-go instances if the instance type priority list does not include sufficient spot alternatives — verify the Auto Scaling group configuration and instance type priority ordering.
  • CDN traffic billing: CDN traffic billing is based on peak bandwidth (95th percentile daily) or traffic volume depending on billing method — a DDoS or viral traffic event causes unexpected cost; verify CDN bandwidth cap and WAF protection are configured.
  • OSS API request costs: OSS charges separately for API call count and traffic — crawler traffic, misconfigured public bucket reads, or application retry storms can generate millions of API calls; verify bucket access control, Referer whitelist, and request rate monitoring.
  • Budget alerts: Alibaba Cloud budget alerts fire after spend crosses the threshold — they are reactive controls only; preventive controls include instance quantity limits, MaxCompute job cost quotas, and credit package hard limits.
  • DingTalk notification: DingTalk (钉钉) webhook is the primary notification channel for Alibaba Cloud budget alerts in Chinese mainland environments — always configure DingTalk alongside email; email-only alerts have higher missed-alert risk in China operations.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full cost anomaly review or formatting the final assessment output.
  • Official sources — use when grounding Alibaba Cloud billing service behavior or product feature claims.

Response minimum

Return, at minimum:

  • the billing account context (CN-* vs international, confirmed),
  • the MaxCompute CU vs on-demand billing posture,
  • the ECS spot instance and Auto Scaling cost risk assessment,
  • CDN and OSS API request cost anomaly findings,
  • budget alert and notification channel configuration verdict,
  • remediation playbook completeness assessment,
  • prioritized cost anomaly response actions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.4 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud billing and cost management service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/maxcompute/latest/billing-overview
      - https://www.alibabacloud.com/help/en/maxcompute/latest/maxcompute-query-acceleration
      - https://www.alibabacloud.com/help/en/ecs/user-guide/spot-instances
      - https://www.alibabacloud.com/help/en/auto-scaling/latest/what-is-auto-scaling
      - https://www.alibabacloud.com/help/en/cost-management/latest/overview
      - https://www.alibabacloud.com/help/en/cost-management/latest/budget-alerts
      - https://www.alibabacloud.com/help/en/cdn/user-guide/billing-overview
      - https://www.alibabacloud.com/help/en/oss/product-overview/billing-overview
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud billing model behavior and feature availability. It does not prove the user's current billing state, spend trend, alert configuration, or notification delivery status. Prefer live Alibaba Cloud Cost Management console evidence or sanitized user-provided billing reports for current-state claims. CN-* mainland China billing accounts and international accounts are separate systems — do not assume data or alert configuration transfers between them.
      
    • workflow-and-output.md 3.6 KB
      # Workflow and output contract
      
      Use this reference only when performing a full cost anomaly investigation or FinOps alert pipeline review.
      
      ## Review domains
      
      Check these areas before giving a recommendation:
      
      - Billing account context: CN-* mainland China vs international — confirmed before analysis begins
      - MaxCompute billing mode: CU subscription vs on-demand; CU coverage of actual workload; query cost estimation gates
      - ECS spot interruption: Auto Scaling group instance type priority; pay-as-you-go fallback trigger conditions
      - CDN billing: bandwidth billing model (95th percentile vs traffic); bandwidth cap configured; WAF protection present
      - OSS API request cost: bucket access control; Referer whitelist; request rate monitoring alerts
      - Budget alerts: threshold configuration; notification channels (DingTalk webhook + email); alert lead time
      - Preventive controls: instance quantity limits; MaxCompute job cost quotas; credit package hard limits
      - Remediation playbook: documented response steps per anomaly type; owner assigned; last tested date
      
      ## Safe workflow
      
      1. **Frame the anomaly**
         - Billing account context (CN-* vs international):
         - Anomaly type (MaxCompute / ECS spot / CDN / OSS / other):
         - Anomaly detection source (budget alert / manual review / billing API):
         - Approximate spend delta (sanitized, no specific customer figures):
      2. **Collect evidence**
         - Prefer live Cost Management console screenshots or BSS API output.
         - Otherwise inspect billing reports, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the cost controls**
         - Is the budget alert threshold set below the anomaly spend level?
         - Does the DingTalk webhook deliver notifications reliably in the CN-* context?
         - Are there preventive controls beyond notification-only budgets?
         - Is the Auto Scaling group configured to prefer spot types over pay-as-you-go?
         - Is MaxCompute on-demand billing at risk from unguarded large queries?
      4. **Recommend the smallest safe next step**
         - Prioritize by risk: active cost blowout requiring immediate stop > missing preventive control > missing DingTalk notification > incomplete remediation playbook.
         - If active cost blowout is detected, recommend immediate action before further analysis.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud Cost Anomaly Review: <anomaly scope>
      ## Executive summary
      - Anomaly verdict:
      - Evidence level:
      - Immediate action required:
      ## Billing account context
      - Account type: CN-* mainland China / international
      - Confirmed by:
      ## MaxCompute billing posture
      - Billing mode: CU subscription / on-demand
      - CU coverage: adequate / gap
      - Query cost estimation gate: present / absent
      - Anomaly risk:
      ## ECS spot and Auto Scaling cost risk
      - Spot interruption risk: low / medium / high
      - Pay-as-you-go fallback configured: yes / no
      - Instance type priority order: correct / gap
      ## CDN and OSS cost anomalies
      - CDN bandwidth cap: set / not set
      - CDN WAF protection: present / absent
      - OSS bucket access control: correct / gap
      - OSS Referer whitelist: set / not set
      ## Budget alert and notification configuration
      - Budget threshold set:
      - DingTalk webhook configured:
      - Email notification configured:
      - Preventive controls beyond alerts:
      ## Remediation playbook
      - Documented response steps: present / absent
      - Owner assigned: yes / no
      - Last tested date:
      ## Cost anomaly response prioritization
      1. <action> — priority: <critical/high/medium>, effort: <low/medium/high>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.4 KB
    {
      "id": "alibaba-cost-anomaly-watch-coordinator",
      "name": "Alibaba Cloud Cost Anomaly Watch Coordinator",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Detect and coordinate response to Alibaba Cloud cost anomalies — MaxCompute CU vs on-demand billing mismatch, ECS spot instance interruption cascades, CDN traffic spike billing, OSS API request cost explosions, budget alert → DingTalk notification → remediation playbook.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/maxcompute/latest/billing-overview",
        "https://www.alibabacloud.com/help/en/ecs/user-guide/spot-instances",
        "https://www.alibabacloud.com/help/en/cost-management/latest/overview",
        "https://www.alibabacloud.com/help/en/cdn/user-guide/billing-overview"
      ],
      "security_notes": "Alibaba Cloud cost data is accessible via the billing API — restrict AccessKey permissions for billing API access to read-only (AliyunBSSReadOnlyAccess). China mainland billing accounts and international accounts cannot be consolidated — separate anomaly monitoring pipelines required for each account type.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-cost-anomaly-watch-coordinator",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.5 KB
    ---
    name: alibaba-cost-anomaly-watch-coordinator
    description: Detect and coordinate response to Alibaba Cloud cost anomalies — MaxCompute CU vs on-demand billing mismatch, ECS spot instance interruption cascades, CDN traffic spike billing, OSS API request cost explosions, budget alert → DingTalk notification → remediation playbook.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: finops
    ---
    
    # Alibaba Cloud Cost Anomaly Watch Coordinator
    
    ## Purpose
    
    Act as the Alibaba Cloud FinOps cost anomaly coordinator who identifies billing anomaly patterns, classifies root causes, verifies alert pipeline completeness, and produces actionable remediation playbooks for MaxCompute, ECS spot, CDN, OSS, and other cost spike scenarios.
    
    ## When to use
    
    Use this skill for:
    
    - detecting MaxCompute CU package vs on-demand billing mismatches
    - diagnosing ECS spot instance interruption cascades and Auto Scaling cost blowouts
    - identifying CDN traffic spike billing anomalies
    - investigating OSS API request cost explosions (e.g., unintentional public reads or crawler traffic)
    - auditing budget alert configuration and DingTalk notification channel setup
    - assessing remediation playbook completeness for cost anomaly response
    - distinguishing CN-* mainland China billing account context from international account context
    
    ## Lean operating rules
    
    - Prefer sanitized Alibaba Cloud Cost Management console evidence or BSS API output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
    - Separate confirmed facts from inference. Label each finding explicitly.
    - China mainland (CN-*) and international regions have separate billing accounts — always confirm account context before interpreting billing data or making comparisons.
    - Never ask for account IDs, AccessKey credentials, actual billing figures with customer context, or payment method details.
    - Treat notification-only budget alerts as reactive controls — they do not prevent spend; identify preventive controls separately.
    
    ## Key cost anomaly guidance
    
    - **MaxCompute billing modes**: CU (Subscription) packages the compute capacity; on-demand bills per GB scanned at approximately $0.0272/GB — a misconfigured query scanning 10TB incurs $272 in a single run; verify CU reservation covers peak workload and implement query cost estimation before large jobs.
    - **ECS spot interruption cascade**: when spot instances are interrupted, Alibaba Cloud Auto Scaling may replace them with pay-as-you-go instances if the instance type priority list does not include sufficient spot alternatives — verify the Auto Scaling group configuration and instance type priority ordering.
    - **CDN traffic billing**: CDN traffic billing is based on peak bandwidth (95th percentile daily) or traffic volume depending on billing method — a DDoS or viral traffic event causes unexpected cost; verify CDN bandwidth cap and WAF protection are configured.
    - **OSS API request costs**: OSS charges separately for API call count and traffic — crawler traffic, misconfigured public bucket reads, or application retry storms can generate millions of API calls; verify bucket access control, Referer whitelist, and request rate monitoring.
    - **Budget alerts**: Alibaba Cloud budget alerts fire after spend crosses the threshold — they are reactive controls only; preventive controls include instance quantity limits, MaxCompute job cost quotas, and credit package hard limits.
    - **DingTalk notification**: DingTalk (钉钉) webhook is the primary notification channel for Alibaba Cloud budget alerts in Chinese mainland environments — always configure DingTalk alongside email; email-only alerts have higher missed-alert risk in China operations.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full cost anomaly review or formatting the final assessment output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud billing service behavior or product feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the billing account context (CN-* vs international, confirmed),
    - the MaxCompute CU vs on-demand billing posture,
    - the ECS spot instance and Auto Scaling cost risk assessment,
    - CDN and OSS API request cost anomaly findings,
    - budget alert and notification channel configuration verdict,
    - remediation playbook completeness assessment,
    - prioritized cost anomaly response actions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related