Back to skill

Security audit

huawei-cloud-kubectl-cce-installer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local installer for kubectl and the Huawei Cloud CCE kubectl plugin, with user confirmation required before changing the machine.

Before installing, review the no-change plan, confirm the target --bin-dir, and only approve sudo or source-build fallback if you trust the documented Kubernetes, Huawei OBS, and Gitee sources. Do not provide Huawei credentials during installation; use credential configuration only later if you intentionally access a CCE cluster.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill clearly instructs execution of bundled shell commands and installation actions, but it does not declare any corresponding permissions. This creates a trust and enforcement gap: a consumer or platform may underestimate the skill's ability to execute local system changes, download binaries, or invoke elevated commands.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.