Back to skill

Security audit

Huawei Cloud Cost Estimation & Controlled Provisioning

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Huawei Cloud quoting and provisioning skill with clear safety gates, though it can create billable cloud resources when the user explicitly approves.

Install only if you want an agent to help quote and provision Huawei Cloud resources through your configured hcloud account. Use a least-privilege IAM user, review every quoted cost and --dryrun output, and do not provide AK/SK or tokens in chat. Avoid partner delegated-token workflows unless you have explicit customer authorization and understand the account scope being queried.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The whitelist extends beyond narrowly scoped resource provisioning into direct purchase orders, prepaid subscriptions, billable security tasks, and governance/configuration actions. In an agent setting, this broadens the set of cost-impacting operations the skill may treat as allowed, increasing the risk of unauthorized spending or unintended commercial actions if prompts, parsing, or confirmation logic fail elsewhere.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The document claims it preserves only executable provisioning commands, but the listed items include non-provisioning actions such as orders, subscriptions, policy/configuration changes, and non-independent billing steps. This mismatch can mislead downstream agent logic or reviewers into over-trusting the whitelist, causing unsafe actions to be classified as routine provisioning.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file documents IAM project-enumeration commands (`KeystoneListAuthProjects`, `KeystoneListProjects`) that go beyond the skill’s declared pricing/provisioning scope. Even if read-only, these commands expand access discovery and tenant mapping capabilities, which can leak account structure and enable follow-on misuse when exposed through an agent skill.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The instruction to replace with a customer token for partner-managed scenarios introduces cross-tenant impersonation/delegation behavior that is not justified by a quoting skill. In an agent context, this is especially dangerous because it can normalize credential/context switching and enable unauthorized access to customer project metadata or later actions under another tenant’s authority.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The markdown enumerates many billable create and purchase commands but does not attach an explicit, prominent warning at the command-list level that these operations can incur immediate charges and must not be run without verified user approval. Given this skill is designed to assist with Huawei Cloud provisioning, the contextual danger is elevated because the list is operational guidance for real paid infrastructure actions, not abstract documentation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.