Back to skill

Security audit

huawei-cloud-ascend-small-model-migrate

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent Ascend NPU migration guide, but it embeds and normalizes privileged root SSH access including a concrete-looking password.

Review before installing. Do not use the embedded root credential; assume it is exposed and rotate it if it may be real. Prefer a non-root account, SSH keys or managed secrets, explicit target confirmation, and staging/test hosts before allowing this skill to run Docker, package installation, or profiling commands against an Ascend server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill documentation discloses a concrete root SSH credential ('root/Hhuawei@smb') and host access details, which creates an immediate secret exposure and unauthorized access risk. Anyone with access to the skill can attempt privileged login to the referenced server, leading to full system compromise, data theft, tampering, or lateral movement.

Missing User Warnings

High
Confidence
99% confidence
Finding
The documentation not only exposes a default root credential but presents it as part of the default environment without any safety control, normalization warning, or access restriction. This materially increases the chance that operators or downstream agents will use insecure privileged access patterns, enabling takeover of the target system if the credential is valid.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The acceptance criteria includes examples that instruct direct root SSH access to a target server and operational commands against that environment without any warning, least-privilege guidance, or safety constraints. In a migration skill that is explicitly meant to connect to real Ascend servers and containers, this normalizes high-privilege access and can lead users or downstream agents to perform invasive actions on production-like systems with unnecessary risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.