Back to skill

Security audit

huawei-cloud-rds-troubleshoot

Security checks across malware telemetry and agentic risk

Overview

This is a transparent Huawei Cloud RDS troubleshooting skill with disclosed credential use and user-confirmed RDS changes, and no hidden persistence or exfiltration was found.

Install only if you intend to let an agent help troubleshoot Huawei Cloud RDS. Prefer RDS ReadOnlyAccess for diagnosis, grant write permissions only for confirmed remediation, use short-lived or tightly scoped credentials where possible, and avoid exposing AK/SK values in shell history, shared terminals, or CI logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation explicitly requires AK/SK credentials in the environment for SDK-mode testing but provides no warning about secure handling, scoping, or cleanup of those secrets. In a cloud operations skill focused on live RDS troubleshooting, this increases the chance that operators place long-lived credentials in shell environments, CI logs, or shared terminals, which could expose access to production cloud resources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.