alibaba-oss-data-perimeter-governor
Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-oss-data-perimeter-governor
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud OSS Data Perimeter Governor
Purpose
Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads.
When to use
Use this skill for:
- OSS bucket ACL audit: public-read/write exposure detection and remediation
- Block Public Access (BPA) account-level and bucket-level posture assessment
- object ACL vs bucket ACL conflict resolution
- cross-account access via RAM role: least privilege bucket policy design
- VPC endpoint binding for private OSS access from ECS without public internet routing
- WORM (Object Lock) configuration review and compliance alignment
- MLPS 2.0 Level 3 data residency compliance: cross-region replication restriction verification
- PIPL compliance: personal data transfer from CN-* to international region OSS
Lean operating rules
- Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If a bucket configuration was not verified, say so.
- Challenge vague access policies, unverified public ACL assumptions, and undocumented replication destinations.
- Keep answers scoped, traceable, and explicit about data exposure risk and open questions.
- Load references only when needed; do not pull all deep guidance into short answers.
Key OSS data perimeter guidance
- Public ACL:
public-readorpublic-read-writebucket ACL is the #1 OSS data breach vector — flag CRITICAL and require immediate remediation; Block Public Access is the safest remediation path. - ACL conflict resolution: Object ACL
privatedoes not protect objects in apublic-readbucket accessed via the public bucket URL — always enable Block Public Access (BPA) for uniform enforcement. - Block Public Access: Account-level BPA overrides bucket-level ACL — enable at account level for all regulated environments; do not rely solely on bucket-level policies.
- VPC endpoint: Without an OSS VPC endpoint, traffic from ECS instances routes over the public internet — bind the bucket to a VPC endpoint for private-network-only access.
- WORM (Object Lock): Governance and Compliance mode locks are irreversible for the lock duration — Compliance mode cannot be shortened even by root; always confirm lock period before enabling.
- MLPS 2.0 Level 3: Data stored in CN-* regions classified under MLPS Level 3 cannot replicate to international regions — audit all Cross-Region Replication (CRR) rules for destination region compliance.
- PIPL compliance: Personal data in CN-* OSS buckets subject to PIPL cannot be transferred internationally without a legal basis — verify replication destination and transfer mechanism before enabling CRR.
References
Load these only when needed:
- Workflow and output contract — use when executing the full OSS data perimeter audit or formatting the final governance output.
- Official sources — use when grounding Alibaba Cloud OSS service behavior, ACL semantics, or BPA feature claims.
Response minimum
Return, at minimum:
- the public ACL exposure assessment with CRITICAL flag if applicable,
- the Block Public Access account-level posture,
- the object ACL vs bucket ACL conflict analysis,
- the VPC endpoint binding and private access configuration status,
- the WORM and data protection posture,
- the MLPS 2.0 data residency compliance verdict,
- the prioritized remediation actions with evidence level for each finding.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1.1 KB
# Official sources Use this reference only when you need source grounding for Alibaba Cloud OSS service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/oss/user-guide/block-public-access - https://www.alibabacloud.com/help/en/oss/user-guide/bucket-acl - https://www.alibabacloud.com/help/en/oss/user-guide/use-bucket-policies-to-authorize-other-users-to-access-oss-resources - https://www.alibabacloud.com/help/en/oss/user-guide/oss-interface-for-vpc - https://www.alibabacloud.com/help/en/oss/user-guide/object-lock - https://www.alibabacloud.com/help/en/oss/user-guide/cross-region-replication - https://www.alibabacloud.com/help/en/ram/latest/overview-1 ## Grounding rule Official documentation explains Alibaba Cloud OSS service behavior and feature availability. It does not prove the user's current bucket configuration, ACL settings, replication rules, or compliance posture. Prefer live OSS console evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.9 KB
# Workflow and output contract Use this reference only when performing a full OSS data perimeter audit, ACL conflict analysis, or compliance posture review. ## Audit domains Check these areas before giving a recommendation: - Bucket ACL: public-read, public-read-write, private — flag public access as CRITICAL - Block Public Access (BPA): account-level and bucket-level BPA status - Object ACL vs bucket ACL conflict: uniform access enforcement gaps - Bucket policy: cross-account access, condition restrictions, IP-based controls - VPC endpoint binding: private access enforcement, public internet exposure from ECS - WORM (Object Lock): mode (Governance/Compliance), lock period, irreversibility risk - Cross-Region Replication (CRR): destination regions, MLPS 2.0 and PIPL compliance - Encryption: server-side encryption (SSE-OSS, SSE-KMS) configuration ## Safe workflow 1. **Frame the audit scope** - Buckets in scope and their account context (CN-* vs international): - Regulatory requirements (MLPS 2.0, PIPL, other): - Explicit out-of-scope items: 2. **Collect evidence** - Prefer live OSS console or API evidence if available. - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test the posture** - Are any buckets set to public-read or public-read-write? - Is BPA enabled at the account level? - Do any CRR rules replicate CN-* classified data to international regions? - Are there object ACLs that conflict with the bucket ACL? - What evidence is missing? 4. **Recommend the smallest safe remediation sequence** - Prioritize public ACL remediation above all other findings. - Require explicit review before enabling WORM (Object Lock). - If the safest action is to gather more evidence, say that plainly. ## Output contract Return this structure: ```markdown # Alibaba Cloud OSS Data Perimeter Assessment: <scope> ## Executive summary - Security verdict (pass / warn / fail): - Evidence level: - Critical findings: ## Public ACL exposure - Buckets with public-read or public-read-write: - CRITICAL flag: - Recommended remediation: ## Block Public Access posture - Account-level BPA enabled: - Bucket-level BPA gaps: ## Object ACL vs bucket ACL conflicts - Conflicts detected: - Uniform access enforcement gaps: ## VPC endpoint binding - Endpoint configured: - Public internet exposure from ECS: ## WORM and data protection - Object Lock enabled: - Lock mode and period: - Irreversibility risk: ## MLPS 2.0 data residency compliance - CRR rules to international regions from CN-* classified buckets: - PIPL transfer mechanism: - Compliance verdict: ## Prioritized remediation actions | Priority | Finding | Action | Evidence level | |---|---|---|---| ## Open questions 1. <question> — owner: <owner>, impact: <impact if unresolved> ```
-
-
metadata.json 1.4 KB
{ "id": "alibaba-oss-data-perimeter-governor", "name": "Alibaba Cloud OSS Data Perimeter Governor", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/oss/user-guide/block-public-access", "https://www.alibabacloud.com/help/en/oss/user-guide/bucket-acl", "https://www.alibabacloud.com/help/en/oss/user-guide/use-bucket-policies-to-authorize-other-users-to-access-oss-resources", "https://www.alibabacloud.com/help/en/oss/user-guide/oss-interface-for-vpc" ], "security_notes": "Alibaba Cloud OSS bucket names are globally unique — a publicly accessible bucket with a guessable name exposes data without authentication. OSS Cross-Region Replication (CRR) to international regions from CN-* buckets containing personal data violates PIPL and may violate MLPS 2.0 — verify replication destination region compliance.", "last_verified": "2026-05-09", "path": "skills/alibaba/alibaba-oss-data-perimeter-governor", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 4.1 KB
--- name: alibaba-oss-data-perimeter-governor description: Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-09" category: security --- # Alibaba Cloud OSS Data Perimeter Governor ## Purpose Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads. ## When to use Use this skill for: - OSS bucket ACL audit: public-read/write exposure detection and remediation - Block Public Access (BPA) account-level and bucket-level posture assessment - object ACL vs bucket ACL conflict resolution - cross-account access via RAM role: least privilege bucket policy design - VPC endpoint binding for private OSS access from ECS without public internet routing - WORM (Object Lock) configuration review and compliance alignment - MLPS 2.0 Level 3 data residency compliance: cross-region replication restriction verification - PIPL compliance: personal data transfer from CN-* to international region OSS ## Lean operating rules - Prefer official Alibaba Cloud documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If a bucket configuration was not verified, say so. - Challenge vague access policies, unverified public ACL assumptions, and undocumented replication destinations. - Keep answers scoped, traceable, and explicit about data exposure risk and open questions. - Load references only when needed; do not pull all deep guidance into short answers. ## Key OSS data perimeter guidance - **Public ACL**: `public-read` or `public-read-write` bucket ACL is the #1 OSS data breach vector — flag CRITICAL and require immediate remediation; Block Public Access is the safest remediation path. - **ACL conflict resolution**: Object ACL `private` does not protect objects in a `public-read` bucket accessed via the public bucket URL — always enable Block Public Access (BPA) for uniform enforcement. - **Block Public Access**: Account-level BPA overrides bucket-level ACL — enable at account level for all regulated environments; do not rely solely on bucket-level policies. - **VPC endpoint**: Without an OSS VPC endpoint, traffic from ECS instances routes over the public internet — bind the bucket to a VPC endpoint for private-network-only access. - **WORM (Object Lock)**: Governance and Compliance mode locks are irreversible for the lock duration — Compliance mode cannot be shortened even by root; always confirm lock period before enabling. - **MLPS 2.0 Level 3**: Data stored in CN-* regions classified under MLPS Level 3 cannot replicate to international regions — audit all Cross-Region Replication (CRR) rules for destination region compliance. - **PIPL compliance**: Personal data in CN-* OSS buckets subject to PIPL cannot be transferred internationally without a legal basis — verify replication destination and transfer mechanism before enabling CRR. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full OSS data perimeter audit or formatting the final governance output. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud OSS service behavior, ACL semantics, or BPA feature claims. ## Response minimum Return, at minimum: - the public ACL exposure assessment with CRITICAL flag if applicable, - the Block Public Access account-level posture, - the object ACL vs bucket ACL conflict analysis, - the VPC endpoint binding and private access configuration status, - the WORM and data protection posture, - the MLPS 2.0 data residency compliance verdict, - the prioritized remediation actions with evidence level for each finding.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.