Back to skill

Security audit

huaweicloud-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a broad Huawei Cloud operations skill with real cloud and MaaS execution paths, but the artifacts disclose those capabilities and mostly gate them behind planning, dry-run, and explicit execution flags.

Install only if you intend to let the agent help manage Huawei Cloud resources or MaaS calls. Use a least-privilege hcloud profile or environment credentials, prefer dry-run/plan modes first, review exact submit tokens and commands before live changes, and avoid running Terraform or billing/account-wide reads in directories or accounts that contain sensitive production state unless you are comfortable with that scope.

SkillSpector could not complete.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/cbh_stack/main.tf.txt:35

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/dcs_stack/main.tf.txt:39

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/dms_stack/main.tf.txt:44

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/ecs_elb_rds_stack/main.tf.txt:118

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/iam_stack/main.tf.txt:48

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/nat_vpc_peering_stack/main.tf.txt:66

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/oms_stack/main.tf.txt:76

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_mysql_eip_stack/main.tf.txt:58

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_mysql_stack/main.tf.txt:58

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_postgresql_ha_stack/main.tf.txt:61

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_read_replica_stack/main.tf.txt:73

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_sqlserver_stack/main.tf.txt:58

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
examples/terraform/rds_stack/main.tf.txt:56