Claude Cursor GitHub Copilot Skill

alibaba-oss-data-perimeter-governor

Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-oss-data-perimeter-governor-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-oss-data-perimeter-governor
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud OSS Data Perimeter Governor

Purpose

Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads.

When to use

Use this skill for:

  • OSS bucket ACL audit: public-read/write exposure detection and remediation
  • Block Public Access (BPA) account-level and bucket-level posture assessment
  • object ACL vs bucket ACL conflict resolution
  • cross-account access via RAM role: least privilege bucket policy design
  • VPC endpoint binding for private OSS access from ECS without public internet routing
  • WORM (Object Lock) configuration review and compliance alignment
  • MLPS 2.0 Level 3 data residency compliance: cross-region replication restriction verification
  • PIPL compliance: personal data transfer from CN-* to international region OSS

Lean operating rules

  • Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
  • Separate confirmed facts from inference. If a bucket configuration was not verified, say so.
  • Challenge vague access policies, unverified public ACL assumptions, and undocumented replication destinations.
  • Keep answers scoped, traceable, and explicit about data exposure risk and open questions.
  • Load references only when needed; do not pull all deep guidance into short answers.

Key OSS data perimeter guidance

  • Public ACL: public-read or public-read-write bucket ACL is the #1 OSS data breach vector — flag CRITICAL and require immediate remediation; Block Public Access is the safest remediation path.
  • ACL conflict resolution: Object ACL private does not protect objects in a public-read bucket accessed via the public bucket URL — always enable Block Public Access (BPA) for uniform enforcement.
  • Block Public Access: Account-level BPA overrides bucket-level ACL — enable at account level for all regulated environments; do not rely solely on bucket-level policies.
  • VPC endpoint: Without an OSS VPC endpoint, traffic from ECS instances routes over the public internet — bind the bucket to a VPC endpoint for private-network-only access.
  • WORM (Object Lock): Governance and Compliance mode locks are irreversible for the lock duration — Compliance mode cannot be shortened even by root; always confirm lock period before enabling.
  • MLPS 2.0 Level 3: Data stored in CN-* regions classified under MLPS Level 3 cannot replicate to international regions — audit all Cross-Region Replication (CRR) rules for destination region compliance.
  • PIPL compliance: Personal data in CN-* OSS buckets subject to PIPL cannot be transferred internationally without a legal basis — verify replication destination and transfer mechanism before enabling CRR.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full OSS data perimeter audit or formatting the final governance output.
  • Official sources — use when grounding Alibaba Cloud OSS service behavior, ACL semantics, or BPA feature claims.

Response minimum

Return, at minimum:

  • the public ACL exposure assessment with CRITICAL flag if applicable,
  • the Block Public Access account-level posture,
  • the object ACL vs bucket ACL conflict analysis,
  • the VPC endpoint binding and private access configuration status,
  • the WORM and data protection posture,
  • the MLPS 2.0 data residency compliance verdict,
  • the prioritized remediation actions with evidence level for each finding.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.1 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud OSS service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/oss/user-guide/block-public-access
      - https://www.alibabacloud.com/help/en/oss/user-guide/bucket-acl
      - https://www.alibabacloud.com/help/en/oss/user-guide/use-bucket-policies-to-authorize-other-users-to-access-oss-resources
      - https://www.alibabacloud.com/help/en/oss/user-guide/oss-interface-for-vpc
      - https://www.alibabacloud.com/help/en/oss/user-guide/object-lock
      - https://www.alibabacloud.com/help/en/oss/user-guide/cross-region-replication
      - https://www.alibabacloud.com/help/en/ram/latest/overview-1
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud OSS service behavior and feature availability. It does not prove the user's current bucket configuration, ACL settings, replication rules, or compliance posture. Prefer live OSS console evidence or sanitized user-provided evidence for current-state claims.
      
    • workflow-and-output.md 2.9 KB
      # Workflow and output contract
      
      Use this reference only when performing a full OSS data perimeter audit, ACL conflict analysis, or compliance posture review.
      
      ## Audit domains
      
      Check these areas before giving a recommendation:
      
      - Bucket ACL: public-read, public-read-write, private — flag public access as CRITICAL
      - Block Public Access (BPA): account-level and bucket-level BPA status
      - Object ACL vs bucket ACL conflict: uniform access enforcement gaps
      - Bucket policy: cross-account access, condition restrictions, IP-based controls
      - VPC endpoint binding: private access enforcement, public internet exposure from ECS
      - WORM (Object Lock): mode (Governance/Compliance), lock period, irreversibility risk
      - Cross-Region Replication (CRR): destination regions, MLPS 2.0 and PIPL compliance
      - Encryption: server-side encryption (SSE-OSS, SSE-KMS) configuration
      
      ## Safe workflow
      
      1. **Frame the audit scope**
         - Buckets in scope and their account context (CN-* vs international):
         - Regulatory requirements (MLPS 2.0, PIPL, other):
         - Explicit out-of-scope items:
      2. **Collect evidence**
         - Prefer live OSS console or API evidence if available.
         - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the posture**
         - Are any buckets set to public-read or public-read-write?
         - Is BPA enabled at the account level?
         - Do any CRR rules replicate CN-* classified data to international regions?
         - Are there object ACLs that conflict with the bucket ACL?
         - What evidence is missing?
      4. **Recommend the smallest safe remediation sequence**
         - Prioritize public ACL remediation above all other findings.
         - Require explicit review before enabling WORM (Object Lock).
         - If the safest action is to gather more evidence, say that plainly.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud OSS Data Perimeter Assessment: <scope>
      ## Executive summary
      - Security verdict (pass / warn / fail):
      - Evidence level:
      - Critical findings:
      ## Public ACL exposure
      - Buckets with public-read or public-read-write:
      - CRITICAL flag:
      - Recommended remediation:
      ## Block Public Access posture
      - Account-level BPA enabled:
      - Bucket-level BPA gaps:
      ## Object ACL vs bucket ACL conflicts
      - Conflicts detected:
      - Uniform access enforcement gaps:
      ## VPC endpoint binding
      - Endpoint configured:
      - Public internet exposure from ECS:
      ## WORM and data protection
      - Object Lock enabled:
      - Lock mode and period:
      - Irreversibility risk:
      ## MLPS 2.0 data residency compliance
      - CRR rules to international regions from CN-* classified buckets:
      - PIPL transfer mechanism:
      - Compliance verdict:
      ## Prioritized remediation actions
      | Priority | Finding | Action | Evidence level |
      |---|---|---|---|
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.4 KB
    {
      "id": "alibaba-oss-data-perimeter-governor",
      "name": "Alibaba Cloud OSS Data Perimeter Governor",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/oss/user-guide/block-public-access",
        "https://www.alibabacloud.com/help/en/oss/user-guide/bucket-acl",
        "https://www.alibabacloud.com/help/en/oss/user-guide/use-bucket-policies-to-authorize-other-users-to-access-oss-resources",
        "https://www.alibabacloud.com/help/en/oss/user-guide/oss-interface-for-vpc"
      ],
      "security_notes": "Alibaba Cloud OSS bucket names are globally unique — a publicly accessible bucket with a guessable name exposes data without authentication. OSS Cross-Region Replication (CRR) to international regions from CN-* buckets containing personal data violates PIPL and may violate MLPS 2.0 — verify replication destination region compliance.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-oss-data-perimeter-governor",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.1 KB
    ---
    name: alibaba-oss-data-perimeter-governor
    description: Govern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: security
    ---
    
    # Alibaba Cloud OSS Data Perimeter Governor
    
    ## Purpose
    
    Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads.
    
    ## When to use
    
    Use this skill for:
    
    - OSS bucket ACL audit: public-read/write exposure detection and remediation
    - Block Public Access (BPA) account-level and bucket-level posture assessment
    - object ACL vs bucket ACL conflict resolution
    - cross-account access via RAM role: least privilege bucket policy design
    - VPC endpoint binding for private OSS access from ECS without public internet routing
    - WORM (Object Lock) configuration review and compliance alignment
    - MLPS 2.0 Level 3 data residency compliance: cross-region replication restriction verification
    - PIPL compliance: personal data transfer from CN-* to international region OSS
    
    ## Lean operating rules
    
    - Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
    - Separate confirmed facts from inference. If a bucket configuration was not verified, say so.
    - Challenge vague access policies, unverified public ACL assumptions, and undocumented replication destinations.
    - Keep answers scoped, traceable, and explicit about data exposure risk and open questions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## Key OSS data perimeter guidance
    
    - **Public ACL**: `public-read` or `public-read-write` bucket ACL is the #1 OSS data breach vector — flag CRITICAL and require immediate remediation; Block Public Access is the safest remediation path.
    - **ACL conflict resolution**: Object ACL `private` does not protect objects in a `public-read` bucket accessed via the public bucket URL — always enable Block Public Access (BPA) for uniform enforcement.
    - **Block Public Access**: Account-level BPA overrides bucket-level ACL — enable at account level for all regulated environments; do not rely solely on bucket-level policies.
    - **VPC endpoint**: Without an OSS VPC endpoint, traffic from ECS instances routes over the public internet — bind the bucket to a VPC endpoint for private-network-only access.
    - **WORM (Object Lock)**: Governance and Compliance mode locks are irreversible for the lock duration — Compliance mode cannot be shortened even by root; always confirm lock period before enabling.
    - **MLPS 2.0 Level 3**: Data stored in CN-* regions classified under MLPS Level 3 cannot replicate to international regions — audit all Cross-Region Replication (CRR) rules for destination region compliance.
    - **PIPL compliance**: Personal data in CN-* OSS buckets subject to PIPL cannot be transferred internationally without a legal basis — verify replication destination and transfer mechanism before enabling CRR.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full OSS data perimeter audit or formatting the final governance output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud OSS service behavior, ACL semantics, or BPA feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the public ACL exposure assessment with CRITICAL flag if applicable,
    - the Block Public Access account-level posture,
    - the object ACL vs bucket ACL conflict analysis,
    - the VPC endpoint binding and private access configuration status,
    - the WORM and data protection posture,
    - the MLPS 2.0 data residency compliance verdict,
    - the prioritized remediation actions with evidence level for each finding.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related