Back to skill

Security audit

huawei-cloud-icp-process-guidance

Security checks across malware telemetry and agentic risk

Overview

This looks like a real Huawei Cloud ICP filing Q&A skill, but it asks agents to install and use a broad third-party search dependency and can send filing questions to Exa without explicit user consent or tight source limits.

Install only if you are comfortable with the optional Agent Reach/Exa dependency. Treat search-backed answers as supplemental, avoid putting personal IDs, company secrets, domain credentials, or full filing records into prompts, and verify filing steps against Huawei Cloud or MIIT official sources before changing DNS, uploading identity documents, or canceling filings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill is presented as an out-of-the-box ICP filing Q&A assistant, but the file also documents index-building behavior that parses local Markdown and writes index.json. This mismatch can mislead operators about what the skill actually does, weakening review and permission decisions; if enabled at runtime, content-processing and file-write logic expands the attack surface beyond simple retrieval.

Intent-Code Divergence

Low
Confidence
92% confidence
Finding
The document presents a source attribution date of '2025-12-31' while the embedded metadata shows older source/update dates, creating an internal contradiction about provenance and recency. In a compliance guidance skill, users may rely on apparent timeliness to make irreversible备案注销 decisions, so stale or misrepresented dates can mislead users into following outdated regulatory or platform procedures.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document asserts that App-side claiming/ICP filing is supported, but the cited evidence only substantiates PC-side steps. In a compliance/process guidance skill, unsupported capability claims can mislead users into taking the wrong channel, delay filings, and cause failed submissions or missed regulatory deadlines. The domain context makes this more sensitive because users rely on precise procedural accuracy for official备案 actions.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The document expands the skill from a closed knowledge-base Q&A tool into one that performs live web searches, which increases its attack surface and can cause the agent to ingest untrusted, potentially manipulated content. In a compliance/regulatory guidance skill, this is risky because users may receive incorrect or policy-conflicting advice sourced from third-party or stale web pages despite the skill’s stated narrow, knowledge-base-driven scope.

Context-Inappropriate Capability

Low
Confidence
89% confidence
Finding
Allowing searches for community/forum 'practical experience' introduces low-trust, unofficial content into a regulatory guidance workflow. Such sources can contain inaccurate, outdated, or adversarial instructions, making prompt/data poisoning and user misguidance more likely, especially when the skill is supposed to answer narrowly about Huawei Cloud ICP filing.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to send user-derived queries to the external Exa search service when KB coverage is low or when the user asks for recent information, but it does not require a clear user-facing notice or consent before transmitting that content. User questions about filing issues may contain personal, business, or regulatory details, so silent forwarding to a third party creates privacy and data-handling risk.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs users to upload identity documents, domain real-name verification screenshots, and complete video verification, but does not include any user-facing privacy notice, sensitivity warning, or safe-handling guidance for personal data. In a document centered on regulatory filing materials, this omission increases the risk of unnecessary disclosure, oversharing, or insecure submission of highly sensitive personal and corporate information.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The guidance tells users to disable DNS resolution before filing but omits any warning that doing so can make a live site unreachable, interrupt dependent services, or cause avoidable downtime. In a procedural support skill, incomplete operational instructions can directly lead users to disrupt production services, especially if they follow the steps without understanding traffic impact.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The acceptance criteria says the skill should activate 'when the user's question matches trigger conditions' but does not define concrete matching rules or boundaries. In a retrieval/Q&A skill that is supposed to answer only Huawei Cloud ICP filing questions and refuse unrelated topics, vague activation criteria can cause over-triggering, scope bypass, and accidental handling of out-of-domain input, which weakens safety and policy enforcement.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.