Back to skill

Security audit

huawei-cloud-cce-query

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent read-only Huawei Cloud CCE query helper, with credential and CLI-installation risks users should handle carefully.

Install only if you need Huawei Cloud CCE inventory queries. Use a least-privilege read-only IAM policy, prefer short-lived or tightly scoped credentials, avoid pasting secrets into shared shell history, and review the downloaded hcloud CLI source before using sudo installation steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide shows users how to set access keys directly via CLI commands and environment variables without warning that secrets may be stored in shell history, local CLI configuration, or exposed to other local processes. In a cloud administration context, this increases the risk of credential leakage and subsequent unauthorized access to Huawei Cloud resources.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.