Back to skill

Security audit

huawei-cloud-dcs-list

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only Huawei Cloud DCS inventory helper, with credential-handling caveats users should manage carefully.

Before installing, use a least-privilege DCS read-only IAM policy, avoid pasting real AK/SK values into shared terminals or persistent shell history, unset temporary environment variables after use, and verify the Huawei CLI download source before running sudo installation steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guide instructs users to set long-lived access keys directly on the command line and in environment variables without warning that shell history, terminal logging, process inspection, and inherited environments can expose those credentials. In a cloud administration context, leaked AK/SK pairs could permit unauthorized access to Huawei Cloud resources well beyond this read-only DCS use case.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.