Back to skill

Security audit

CloudQ International

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Tencent CloudQ skill, but it includes under-disclosed cloud-account mutation paths that users should review before installing.

Install only if you are comfortable sending cloud-management prompts to Tencent CloudQ and using Tencent Cloud AK/SK environment credentials. Use a limited sub-account, review Smart Advisor enablement before consenting, and do not run cleanup.py with --cloud unless you intend to delete the advisor CAM role.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s actual scope is much narrower than the declared purpose. It is specifically an environment diagnostic/bootstrap script for Tencent Cloud International Smart Advisor/CloudQ, not a general cloud operations skill across multiple providers. Its main behaviors are local environment inspection, remote version lookup, credential presence and validity checks, Smart Advisor authorization status checks, and optional service enablement through a write API call. While these actions are tangentially related to Tencent Cloud operations, they do not match the broad declared capability set and do not support the multi-cloud claims. The optional enabling of Smart Advisor is also a material write action that should be explicitly disclosed. Therefore, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad multi-cloud advisory and operations skill focused on architecture analysis, diagrams, monitoring, diagnostics, optimization, and best-practice guidance. The actual code does none of those things. Instead, it is a cleanup/uninstall-style script specifically for Tencent CloudQ/Advisor local state and an optional Tencent CAM role. This is a materially different primary purpose and includes undeclared destructive capabilities affecting local files, environment variables, and cloud IAM-style resources. While it is Tencent-related, it does not implement the described assistant features and is not a general multi-cloud operations tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code chunk does not implement cloud architecture analysis, AIOps, ChatOps, CloudOps, resource inventory, cost optimization, security/compliance checks, or any multi-cloud operational functionality described in the declared purpose. Instead, it is an internal i18n utility for selecting a language and translating text templates. While such a module could support a larger cloud operations skill, this specific code's primary purpose is materially different from the declared end-user functionality, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Yes, this is a mismatch at the code-chunk level. The declared purpose describes a broad cloud architecture and operations skill with many substantive capabilities, but the provided code does not implement any of those behaviors. It only appears to be a localization package initializer for language text resources. This is not an undeclared dangerous capability; rather, the actual code is a supporting i18n component whose primary purpose is materially different from the declared end-user functionality. Since the evaluation is based on the supplied code chunk, the description does not accurately represent what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a mismatch because the declared description presents a large, multi-cloud operational assistant covering many architecture and CloudOps use cases across Tencent Cloud, AWS, Alibaba Cloud, and others. The actual code chunk does not implement those capabilities. It is a localization file containing English translations for Tencent Cloud Smart Advisor support scripts, especially environment verification, credential checks, Smart Advisor enablement, version checks, API/task helper usage, and cleanup of credentials/environment variables/cloud roles. While some strings relate to Smart Advisor and CloudQ operations mentioned in the description, the actual behavior evidenced here is much narrower and Tencent-only, and it also includes cleanup/deletion operations not represented as a core declared purpose. Therefore the declared description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents this skill as a comprehensive multi-cloud architecture/AIOps/CloudOps capability covering Tencent Cloud, AWS, Alibaba Cloud, and many higher-level operational analyses. The supplied code, however, is only a low-level Tencent Cloud API client that computes TC3 signatures, loads credentials, sends HTTPS POST requests, and parses results. It is further constrained by an explicit service whitelist to advisor, cam, and sts, which materially limits what resources and operations it can perform. There is no implementation for AWS, Alibaba Cloud, architecture diagram generation, smart advisor logic, monitoring, chaos drills, diagnostics, proactive alerts, cost optimization, security/compliance analysis, or other broad features claimed in the description. Therefore the declared description substantially overstates and misrepresents the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description presents a broad, user-facing multi-cloud operations and architecture skill covering many analysis and management functions across Tencent Cloud, AWS, Alibaba Cloud, and more. The supplied code does not implement those capabilities. It is a focused helper script for Tencent Cloud CloudQ asynchronous task management only: querying task status, cancelling tasks, and polling until completion using Tencent Cloud Advisor APIs. While this could support a larger Tencent Cloud workflow, the code chunk itself has a materially narrower and different purpose than the declared skill description, and it does not demonstrate the stated multi-cloud or architecture/AIOps feature set.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description presents this skill as a comprehensive multi-cloud operations and advisory capability spanning Tencent Cloud, AWS, Alibaba Cloud, and many concrete cloud management functions. The supplied code, however, is only an API client for Tencent Cloud CloudQ on the international site. Its primary behavior is request signing, credential loading, sending a question to advisor.ai.tencentcloudapi.com, and parsing SSE or async task acceptance responses. While CloudQ may conceptually answer some of the described topics, that functionality is not implemented in this code chunk; the code itself neither integrates with AWS/Alibaba nor performs direct architecture assessment, resource inventory, cost/security/compliance analysis, chaos drills, alerts, or similar operations. This is a material scope mismatch, especially because the declared purpose is broad and multi-cloud while the implementation is Tencent-only chat API plumbing.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
88% confidence
Finding

The instruction to display backend responses verbatim creates a direct prompt/response exfiltration channel from the remote service to the user with no local filtering or policy mediation. If the remote endpoint is compromised or returns hidden system prompts, internal instructions, malicious links, or unsafe operational guidance, the skill is explicitly told to pass them through unchanged.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

python3 {baseDir}/scripts/tcloud_sse_api.py 'Who are you' --source --session-id "$SID"

text

Display rule: pass through the remote response as-is — no rewriting, no summarizing.

**If the remote call fails**, use the following fallback introduction (label it with "offline fallback below — for the full introduction, ask via conversation"):

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
88% confidence
Finding

As with the identity flow, the feature-query flow mandates verbatim backend output and forbids local rewriting, making the remote service an unfiltered content source. That creates risk of prompt disclosure, unsafe instructions, malicious content injection, or deceptive consent-related messaging being relayed directly to users.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

python3 {baseDir}/scripts/tcloud_sse_api.py 'What features and capabilities does CloudQ have' --source --session-id "$SID"

text

Display rule: send **only the feature-query command above** and display the backend response verbatim — one remote call; do **not** also run the §0 self-introduction call for this question type. If the query fails after the single retry allowed by §5, fall back to the three capability bullets of the offline introduction in §0 (🤖 / 🧠 / ☁️), labeled "these are known feature directions — query the API for the full, up-to-date capability set".

## 0.2 Routing Rules

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
| 1 | "help", "how to use", "帮助" | Brief usage note: just describe your cloud management needs in natural language |
| 2 | "cancel", "never mind", "取消" | "OK, cancelled." |
| 3 | "thanks", "ok", "bye", "谢谢" | Brief acknowledgment |
| 4 | "start over", "new topic", "clear history", "重新开始" | "OK, starting a new conversation." — regenerate session_id |
| 5 | "who are you", "what is CloudQ", "你是谁" | Forward to remote (see §0); use the offline fallback if remote fails |

### 0.2.2 Capability Boundaries (Reject Outright)

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script performs outbound network requests to both Tencent Cloud APIs and the ClawHub service, yet the declared permissions apparently do not include network access. Undeclared network capability is risky because it can transmit metadata or use cloud credentials for remote actions without the permission model accurately informing reviewers or users.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script performs outbound network requests to both Tencent Cloud APIs and the ClawHub service, yet the declared permissions apparently do not include network access. Undeclared network capability is risky because it can transmit metadata or use cloud credentials for remote actions without the permission model accurately informing reviewers or users.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cleanup.py (reported line 15)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cleanup.py (reported line 44)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cleanup.py (reported line 162)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cleanup.py (reported line 164)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credential_manager.py (reported line 4)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credential_manager.py (reported line 17)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/locales/en.py (reported line 106)May include surrounding context.

python
#!/usr/bin/env python3
"""凭证管理(国际站:仅 AK/SK 环境变量)

国际站凭证只从环境变量读取 AK/SK。若检测到本地 credential.json
(如其他版本残留),输出忽略提示后照常使用环境变量(防止残留文件遮蔽 AK/SK)。

凭证文件与配置目录仅由 cleanup.py 清理时使用(load/clear 接口保留)。

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/locales/en.py (reported line 58)May include surrounding context.

python
'已生成 PowerShell 清理脚本: {path}': 'PowerShell cleanup script generated: {path}',
    '已生成清理脚本: {path}': 'Cleanup script generated: {path}',
    '已跳过版本更新检查(--skip-update)': 'Version update check skipped (--skip-update)',
    '建议前往 SkillHub 或 ClawHub 更新此 Skill': 'It is recommended to update this Skill via SkillHub or ClawHub',
    '开通方式:请在对话中同意开通,或运行以下命令:': 'To enable it: agree in the conversation, or run the following command:',
    '当前凭证不允许调用 {service} 服务(允许: {allowed})。{hint}': 'The current credentials are not allowed to call the {service} service (allowed: {allowed}). {hint}',
    '当前已是最新版本: {local_ver}': 'Already up to date: {local_ver}',

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/locales/en.py (reported line 131)May include surrounding context.

python
'已生成 PowerShell 清理脚本: {path}': 'PowerShell cleanup script generated: {path}',
    '已生成清理脚本: {path}': 'Cleanup script generated: {path}',
    '已跳过版本更新检查(--skip-update)': 'Version update check skipped (--skip-update)',
    '建议前往 SkillHub 或 ClawHub 更新此 Skill': 'It is recommended to update this Skill via SkillHub or ClawHub',
    '开通方式:请在对话中同意开通,或运行以下命令:': 'To enable it: agree in the conversation, or run the following command:',
    '当前凭证不允许调用 {service} 服务(允许: {allowed})。{hint}': 'The current credentials are not allowed to call the {service} service (allowed: {allowed}). {hint}',
    '当前已是最新版本: {local_ver}': 'Already up to date: {local_ver}',

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest trigger is extremely broad and can cause the skill to activate for many ordinary cloud-related prompts, routing user input and context to a remote backend more often than expected. In a system with automatic skill invocation, overbroad matching increases accidental data exposure and makes consent boundaries weaker.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill requests Bash and Write while primarily acting as a remote CloudQ proxy, and the write-capable flows include enabling Smart Advisor and cleanup operations. Excess capability broadens the blast radius if the skill is misused, compromised, or socially engineered into performing local or account-changing actions that are not strictly necessary for ordinary read-only question answering.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/check_env.py (reported line 150)May include surrounding context.

python
def _get_info_via_clawhub(slug: str) -> Optional[dict]:
    import subprocess
    result = subprocess.run(
        ["clawhub", "inspect", slug, "--versions", "--json"],
        capture_output=True, text=True, timeout=VERSION_CHECK_TIMEOUT,
    )

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/tcloud_async_task.py:91

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/tcloud_sse_api.py:208