Back to skill

Security audit

huawei-cloud-vbs-list

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only Huawei Cloud backup listing helper, with some installation and trigger-scope cautions but no evidence of hidden or destructive behavior.

Install only if you intend to query Huawei Cloud CBR/VBS backup inventory. Use a least-privilege IAM user with cbr:backups:list, do not paste AK/SK into chat, and verify the hcloud installer from Huawei before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes very broad terms such as '备份', 'backup list', and 'Cloud Backup', which can cause the skill to activate for unrelated backup contexts. Over-broad activation can route users into the wrong cloud-specific workflow, leading to unintended execution of cloud inventory commands against configured accounts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide tells users to fetch and immediately execute a remote installer via curl and bash without any integrity verification, signature check, pinned checksum, or supply-chain warning. If the hosting location, DNS, transport path, or upstream artifact were compromised, users could run attacker-controlled code on their machines with the same privileges as the shell session.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.