Forecast cash, calculate runway, model financing, and prepare finance decisions for boards and founders.
Security
Alibaba Cloud Security Center SAS
Manage and verify Alibaba Cloud Security Center resources through OpenAPI or official SDKs.
What it does
Manage Alibaba Cloud Security Center resources through RPC OpenAPI calls using official SDKs or OpenAPI Explorer. The workflow discovers Sas API schemas, confirms region and resource identifiers, performs list, configuration, or status operations, then verifies results with describe or list APIs. Artifacts and API response summaries are saved under the designated output directory with key parameters for reproducibility.
When to use it
- Inventorying Security Center resources
- Updating Security Center configuration
- Querying resource or service status
- Troubleshooting through describe and query APIs
The skill document
Category: service
Security Center
Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for Security Center.
Workflow
- Confirm region, resource identifiers, and desired action.
- Discover API list and required parameters (see references).
- Call API with SDK or OpenAPI Explorer.
- Verify results with describe/list APIs.
AccessKey priority (must follow)
- Environment variables:
ALICLOUD_ACCESS_KEY_ID/ALICLOUD_ACCESS_KEY_SECRET/ALICLOUD_REGION_IDRegion policy:ALICLOUD_REGION_IDis an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. - Shared config file:
~/.alibabacloud/credentials
API discovery
- Product code:
Sas - Default API version:
2021-01-14 - Use OpenAPI metadata endpoints to list APIs and get schemas (see references).
High-frequency operation patterns
- Inventory/list: prefer
List*/Describe*APIs to get current resources. - Change/configure: prefer
Create*/Update*/Modify*/Set*APIs for mutations. - Status/troubleshoot: prefer
Get*/Query*/Describe*StatusAPIs for diagnosis.
Minimal executable quickstart
Use metadata-first discovery before calling business APIs:
python scripts/list_openapi_meta_apis.py
Optional overrides:
python scripts/list_openapi_meta_apis.py --product-code --version
The script writes API inventory artifacts under the skill output directory.
Output policy
If you need to save responses or generated artifacts, write them under:
output/alicloud-security-center-sas/
Validation
mkdir -p output/alicloud-security-center-sas
for f in skills/security/host/alicloud-security-center-sas/scripts/*.py; do
python3 -m py_compile "$f"
done
echo "py_compile_ok" > output/alicloud-security-center-sas/validate.txt
Pass criteria: command exits 0 and output/alicloud-security-center-sas/validate.txt is generated.
Output And Evidence
- Save artifacts, command outputs, and API response summaries under
output/alicloud-security-center-sas/. - Include key parameters (region/resource id/time range) in evidence files for reproducibility.
Prerequisites
- Configure least-privilege Alibaba Cloud credentials before execution.
- Prefer environment variables:
ALICLOUD_ACCESS_KEY_ID,ALICLOUD_ACCESS_KEY_SECRET, optionalALICLOUD_REGION_ID. - If region is unclear, ask the user before running mutating operations.
References
- Sources:
references/sources.md
Questions people ask
- How does it choose the Security Center API to call?
- It uses OpenAPI metadata to list APIs and inspect required schemas for product code `Sas`, with `2021-01-14` as the default API version.
- Where does it get Alibaba Cloud credentials and region settings?
- It first checks `ALICLOUD_ACCESS_KEY_ID`, `ALICLOUD_ACCESS_KEY_SECRET`, and optional `ALICLOUD_REGION_ID`, then falls back to `~/.alibabacloud/credentials`. If the region is unclear, it asks before mutating resources.
- How are API results verified and recorded?
- Changes are checked with describe or list APIs. Artifacts, command outputs, and response summaries go to `output/alicloud-security-center-sas/`, including region, resource ID, and time range when relevant.
Related skills
Builds CMO-level strategy, budgets, channel plans, team design, and pipeline targets tied to revenue.
Coordinate local multi-agent work with shared state, budget checks, validation, and advisory permission gates.
Monitor signed advisories, match affected installed skills, and gate risky installs or removals on approval.
Audit, reconcile, and record machine-facing entity identity with evidence and provenance.
Monitor NVD CVEs, community advisories, and pre-CVE GitHub advisories in one agent security feed.