Back to skill

Security audit

huawei-cloud-swr-namespace-list

Security checks across malware telemetry and agentic risk

Overview

This is a coherent read-only Huawei Cloud namespace listing skill with credential and install hygiene caveats but no hidden or destructive behavior.

Install only if you need Huawei Cloud SWR namespace visibility. Use a least-privilege IAM user with SWR read-only permissions, avoid pasting real secrets into shared terminals or logs, verify the KooCLI download source before using sudo, and do not pass untrusted region or namespace values to the test script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide instructs users to place cloud access keys directly into CLI configuration and shell environment variables without any warning about secret exposure, shell history, process inspection, shared terminals, or secure secret storage. In a cloud administration context, these credentials can grant broad access to Huawei Cloud resources, so insecure handling materially increases the risk of account compromise.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.