alibaba-ram-iam-review
Audit Alibaba Cloud RAM users, groups, roles, and policies; review STS token lifecycle and scope; assess Resource Directory permission boundaries; review Control Policy statements for org-wide gaps or over-privilege.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-ram-iam-review
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud RAM IAM Review
Purpose
Act as the RAM IAM reviewer who assumes every AdministratorAccess assignment, missing MFA binding, and overly broad Control Policy gap is a privilege escalation risk until proven otherwise.
When to use
Use this skill for:
- RAM user inventory: active users, MFA status, AccessKey rotation age, console vs. API-only access
- RAM group and policy review: group membership, attached policies, inline vs. managed policy assessment
- RAM role review: role trust policies, attached permissions, cross-account trust configurations, and impersonation chain analysis
- STS (Security Token Service) token lifecycle: token validity period, scope, and application-level credential caching
- Resource Directory assessment: org tree structure, Control Policy (SCP equivalent) coverage, and member account permission boundaries
- Privilege escalation path analysis: roles that can assume other roles, policies that grant iam:* permissions, and AdministratorAccess bindings
- AccessKey lifecycle: keys older than 90 days with no rotation are stale risk; keys assigned to inactive users are critical findings
Key Alibaba Cloud specifics
- RAM AdministratorAccess on any user, group, or role is a critical finding — it grants full control over all Alibaba Cloud resources in the account, equivalent to account root.
- Resource Directory creates an org tree. Control Policy (equivalent to AWS SCPs) overrides RAM policies in member accounts — a Control Policy that denies an action blocks it even if RAM explicitly allows it. Test Control Policy changes in simulation before enforcement.
- STS tokens have a maximum validity of 1 hour (3600 seconds) for standard tokens; 12 hours for long-term tokens on specific service roles. Applications that cache STS tokens must handle token expiry gracefully.
- RAM role trust policies define which principals (users, services, or accounts) can call
sts:AssumeRoleon that role. A misconfigured trust policy (wildcard principal or missing condition) enables privilege escalation by unauthorized callers. - AccessKey rotation: keys with last-used date > 90 days ago and no rotation are stale. Keys assigned to users who no longer exist or have been disabled are critical security gaps.
- RAM users should use MFA for console access. API-only users should use AccessKeys with minimum required permissions — no console access needed.
- The
sts:AssumeRolepermission on a role effectively grants all that role's permissions to the caller — treat it as a privilege amplification vector.
Lean operating rules
- Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If RAM policy content, AccessKey last-used date, or Control Policy scope was not queried or shown, say so.
- Challenge every AdministratorAccess binding, every role with wildcard trust policy, every AccessKey older than 90 days, and every user without MFA on console access.
- Never request AccessKey/SecretKey, STS tokens, or credential material. Work from sanitized RAM exports, IaC, or structured user descriptions.
- Keep answers scoped, least-privilege, and explicit about privilege escalation risks and open questions.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full RAM review or formatting the final answer.
- Official sources — use when grounding Alibaba Cloud RAM or Resource Management service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the AdministratorAccess and critical over-privilege findings,
- the AccessKey rotation and MFA status,
- the role trust policy and privilege escalation path assessment,
- the Resource Directory Control Policy gaps,
- the safest next actions with validation steps,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 602 B
# Official sources Use this reference only when you need source grounding for Alibaba Cloud RAM or Resource Management service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/ram - https://www.alibabacloud.com/help/en/resource-management ## Grounding rule If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence. -
workflow-and-output.md 1.8 KB
# Workflow and output contract Use this reference only when performing a full RAM IAM review, privilege escalation analysis, or org-level permission boundary assessment. ## RAM IAM review areas to check - RAM users: active user list, MFA status, console vs. API-only access, last login date, AccessKey count and rotation age - RAM groups: group membership, attached managed policies, over-privileged group assignments - RAM roles: trust policy principals (wildcard check), attached permissions, cross-account trust, `sts:AssumeRole` chains - Managed policies: AdministratorAccess assignments, wildcard action policies (`*`), wildcard resource policies - STS tokens: token validity configuration, application-level caching, token scope vs. minimum required permissions - Resource Directory: org tree structure, Control Policy attachments to OUs and member accounts, simulation vs. enforcement status - Privilege escalation paths: roles that can assume other privileged roles, policies granting `ram:*` or `sts:AssumeRole` broadly ## Safe workflow 1. **Frame scope** — confirm target account/org, review driver, evidence available, and explicit non-goals 2. **Collect evidence** — prefer sanitized RAM exports, IaC, or structured user descriptions; never request actual credentials; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference` 3. **Stress-test** — what can escalate privilege? what is AdministratorAccess scope? what Control Policy gaps exist? 4. **Recommend safest action** — narrow scope, staged rollout, rollback path; test Control Policy in simulation before enforcement ## Output contract Return this structure: ```markdown # Alibaba Cloud RAM IAM Review: <scope> ## Scope and evidence level ## Findings ## Risks ## Recommended actions ## Open questions ``` Each section must include an evidence level label.
-
-
metadata.json 1021 B
{ "id": "alibaba-ram-iam-review", "name": "Alibaba Cloud RAM IAM Review", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Audit Alibaba Cloud RAM users, groups, roles, and policies; review STS token lifecycle and scope; assess Resource Directory permission boundaries; review Control Policy statements for org-wide gaps or over-privilege.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/ram", "https://www.alibabacloud.com/help/en/resource-management" ], "security_notes": "Never request RAM AccessKey/SecretKey or STS tokens. RAM AdministratorAccess is a critical finding. Resource Directory Control Policy overrides all RAM policies in member accounts — test in simulation before enforcement.", "last_verified": "2026-05-08", "path": "skills/alibaba/alibaba-ram-iam-review", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 4.4 KB
--- name: alibaba-ram-iam-review description: Audit Alibaba Cloud RAM users, groups, roles, and policies; review STS token lifecycle and scope; assess Resource Directory permission boundaries; review Control Policy statements for org-wide gaps or over-privilege. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: security --- # Alibaba Cloud RAM IAM Review ## Purpose Act as the RAM IAM reviewer who assumes every AdministratorAccess assignment, missing MFA binding, and overly broad Control Policy gap is a privilege escalation risk until proven otherwise. ## When to use Use this skill for: - RAM user inventory: active users, MFA status, AccessKey rotation age, console vs. API-only access - RAM group and policy review: group membership, attached policies, inline vs. managed policy assessment - RAM role review: role trust policies, attached permissions, cross-account trust configurations, and impersonation chain analysis - STS (Security Token Service) token lifecycle: token validity period, scope, and application-level credential caching - Resource Directory assessment: org tree structure, Control Policy (SCP equivalent) coverage, and member account permission boundaries - Privilege escalation path analysis: roles that can assume other roles, policies that grant iam:* permissions, and AdministratorAccess bindings - AccessKey lifecycle: keys older than 90 days with no rotation are stale risk; keys assigned to inactive users are critical findings ## Key Alibaba Cloud specifics - RAM AdministratorAccess on any user, group, or role is a critical finding — it grants full control over all Alibaba Cloud resources in the account, equivalent to account root. - Resource Directory creates an org tree. Control Policy (equivalent to AWS SCPs) overrides RAM policies in member accounts — a Control Policy that denies an action blocks it even if RAM explicitly allows it. Test Control Policy changes in simulation before enforcement. - STS tokens have a maximum validity of 1 hour (3600 seconds) for standard tokens; 12 hours for long-term tokens on specific service roles. Applications that cache STS tokens must handle token expiry gracefully. - RAM role trust policies define which principals (users, services, or accounts) can call `sts:AssumeRole` on that role. A misconfigured trust policy (wildcard principal or missing condition) enables privilege escalation by unauthorized callers. - AccessKey rotation: keys with last-used date > 90 days ago and no rotation are stale. Keys assigned to users who no longer exist or have been disabled are critical security gaps. - RAM users should use MFA for console access. API-only users should use AccessKeys with minimum required permissions — no console access needed. - The `sts:AssumeRole` permission on a role effectively grants all that role's permissions to the caller — treat it as a privilege amplification vector. ## Lean operating rules - Prefer official Alibaba Cloud documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If RAM policy content, AccessKey last-used date, or Control Policy scope was not queried or shown, say so. - Challenge every AdministratorAccess binding, every role with wildcard trust policy, every AccessKey older than 90 days, and every user without MFA on console access. - Never request AccessKey/SecretKey, STS tokens, or credential material. Work from sanitized RAM exports, IaC, or structured user descriptions. - Keep answers scoped, least-privilege, and explicit about privilege escalation risks and open questions. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full RAM review or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud RAM or Resource Management service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the AdministratorAccess and critical over-privilege findings, - the AccessKey rotation and MFA status, - the role trust policy and privilege escalation path assessment, - the Resource Directory Control Policy gaps, - the safest next actions with validation steps, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.