Back to skill

Security audit

huawei-cloud-iam-role-list

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only Huawei Cloud IAM role inventory helper, with a minor activation-scoping issue to watch for.

Install this only if you want an agent to query Huawei Cloud IAM role metadata using your configured Huawei credentials. Confirm ambiguous requests before running it, use least-privilege credentials with only role-list permission, and do not paste AK/SK secrets into chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger list includes generic phrases such as 'permission list', '查询角色', and '获取角色列表' that may match requests outside Huawei Cloud IAM role enumeration. Overbroad triggers can cause the wrong skill to activate and enumerate sensitive IAM metadata when the user intended a different task, increasing unnecessary credential use and data exposure.

VirusTotal

1/64 vendors flagged this skill as malicious, and 63/64 flagged it as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.