huawei-cloud-find-skills

Security checks across malware telemetry and agentic risk

Overview

This skill is a Huawei Cloud skill finder, but it broadly tells agents to install and run matched skills for almost any Huawei Cloud request without enough user control or risk disclosure.

Review before installing. Use it only for explicit Huawei Cloud skill discovery, and do not let it automatically install or execute matched skills. Before installing any suggested skill, check the publisher, source, permissions, and whether it can modify cloud resources or expose credentials such as kubeconfigs, AK/SK values, or tokens.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill describes itself as "read-only," but its documented workflow explicitly tells the agent to install other skills via package-manager commands. That mismatch can mislead users and downstream agents into underestimating the trust and execution risk of pulling and installing third-party code.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The notes claim only Step 2 requires network access, but Step 3 installation necessarily reaches external registries or repositories to download packages. Misrepresenting network behavior reduces transparency and can bypass user expectations or policy controls around outbound access.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description uses a very broad trigger scope for essentially any Huawei Cloud-related request, increasing the chance this skill is invoked in contexts where it is unnecessary or unsafe. Because the skill can lead to installation of additional skills, broad activation materially expands the attack surface for prompt-driven package installation.

Vague Triggers

High
Confidence
95% confidence
Finding
The instructions say to use this skill for any Huawei Cloud query or management task, then install a matched skill and execute it. This creates an unsafe delegation chain in which normal cloud-management requests are redirected into discovering and installing potentially unreviewed third-party skills, making accidental code execution or tool overreach much more likely.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The installation section provides direct package-manager commands (`npx skills add`, `npx clawhub install`) without any warning that these commands fetch and install third-party content that may execute code or alter agent behavior. In this context, the omission is particularly risky because the skill is designed to discover arbitrary skills from a public repository and encourage immediate installation.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The CLI guidance skill advertises extremely broad triggers such as "Huawei Cloud", "云", "工具", "OBS", "ECS", and general command-line phrases. This can cause the skill to activate on many unrelated requests and steer users into credential/configuration flows, increasing the chance of unintended execution paths or sensitive setup guidance being surfaced without clear user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The Terraform generator is described as activating for very generic verbs like create, deploy, configure, manage, and many common infrastructure nouns. That breadth can cause unintended invocation for broad cloud requests, leading the agent to generate infrastructure-as-code or deployment plans when the user did not explicitly ask for Terraform or provisioning automation.

Credential Access

High
Category
Privilege Escalation
Content
"hibernate cluster",
                                        "awake cluster",
                                        "addon",
                                        "kubeconfig",
                                        "EIP binding",
                                        "CCE 集群",
                                        "创建集群",
Confidence
89% confidence
Finding
kubeconfig

Credential Access

High
Category
Privilege Escalation
Content
"name":  "ucs-cluster-onboarding-manager",
                       "category":  "container",
                       "service":  "ucs",
                       "description":  "Huawei Cloud UCS (Universal Cloud Service) cluster onboarding, lifecycle, and fleet grouping management skill using hcloud CLI.\nUse this skill when the user wants to: (1) register self-managed or CCE clusters to UCS - register/query/remove, (2) manage cluster lifecycle - update/query/list clusters, (3) manage fleet groups - create/delete/query cluster groups, (4) obtain cluster access information and kubeconfig, (5) download federation kubeconfig for multi-cluster access, (6) check UCS resource quotas.\nTrigger: user mentions \"UCS cluster onboarding\", \"UCS 集群纳管\", \"UCS cluster registration\", \"UCS 注册集群\", \"UCS fleet\", \"UCS 舰队\", \"UCS 集群组\", \"cluster group\", \"fleet grouping\", \"UCS kubeconfig\", \"UCS 集群接入\", \"UCS federation\", \"UCS 联邦\", \"UCS 配额\", \"cluster lifecycle\", \"集群生命周期\", \"managed clusters\", \"纳管集群\", \"集群管理\"",
                       "triggers":  [
                                        "user mentions \"UCS cluster onboarding",
                                        "UCS 集群纳管",
Confidence
92% confidence
Finding
kubeconfig

Credential Access

High
Category
Privilege Escalation
Content
"name":  "ucs-cluster-onboarding-manager",
                       "category":  "container",
                       "service":  "ucs",
                       "description":  "Huawei Cloud UCS (Universal Cloud Service) cluster onboarding, lifecycle, and fleet grouping management skill using hcloud CLI.\nUse this skill when the user wants to: (1) register self-managed or CCE clusters to UCS - register/query/remove, (2) manage cluster lifecycle - update/query/list clusters, (3) manage fleet groups - create/delete/query cluster groups, (4) obtain cluster access information and kubeconfig, (5) download federation kubeconfig for multi-cluster access, (6) check UCS resource quotas.\nTrigger: user mentions \"UCS cluster onboarding\", \"UCS 集群纳管\", \"UCS cluster registration\", \"UCS 注册集群\", \"UCS fleet\", \"UCS 舰队\", \"UCS 集群组\", \"cluster group\", \"fleet grouping\", \"UCS kubeconfig\", \"UCS 集群接入\", \"UCS federation\", \"UCS 联邦\", \"UCS 配额\", \"cluster lifecycle\", \"集群生命周期\", \"managed clusters\", \"纳管集群\", \"集群管理\"",
                       "triggers":  [
                                        "user mentions \"UCS cluster onboarding",
                                        "UCS 集群纳管",
Confidence
92% confidence
Finding
kubeconfig

Credential Access

High
Category
Privilege Escalation
Content
"name":  "ucs-cluster-onboarding-manager",
                       "category":  "container",
                       "service":  "ucs",
                       "description":  "Huawei Cloud UCS (Universal Cloud Service) cluster onboarding, lifecycle, and fleet grouping management skill using hcloud CLI.\nUse this skill when the user wants to: (1) register self-managed or CCE clusters to UCS - register/query/remove, (2) manage cluster lifecycle - update/query/list clusters, (3) manage fleet groups - create/delete/query cluster groups, (4) obtain cluster access information and kubeconfig, (5) download federation kubeconfig for multi-cluster access, (6) check UCS resource quotas.\nTrigger: user mentions \"UCS cluster onboarding\", \"UCS 集群纳管\", \"UCS cluster registration\", \"UCS 注册集群\", \"UCS fleet\", \"UCS 舰队\", \"UCS 集群组\", \"cluster group\", \"fleet grouping\", \"UCS kubeconfig\", \"UCS 集群接入\", \"UCS federation\", \"UCS 联邦\", \"UCS 配额\", \"cluster lifecycle\", \"集群生命周期\", \"managed clusters\", \"纳管集群\", \"集群管理\"",
                       "triggers":  [
                                        "user mentions \"UCS cluster onboarding",
                                        "UCS 集群纳管",
Confidence
92% confidence
Finding
kubeconfig

Credential Access

High
Category
Privilege Escalation
Content
"name":  "huawei-cloud-cli-guidance",
                       "category":  "devtools",
                       "service":  "cli",
                       "description":  "Provides guidance for Huawei Cloud KooCLI command-line tool operations. Covers KooCLI installation, IAM authentication configuration, access credential configuration, command construction, common error troubleshooting. Use this skill when users ask about any cloud-related services or wants to operate Huawei Cloud services from the terminal. Triggers: Huawei Cloud, huaweiyun, \"华为云\",\"华为cli\", \"命令行\", KooCLI, hcloud, huaweiyunCLI, Huawei Cloud command line, OBS, ECS, VPC, \"云\", yun, huaweiyun tool, huawei tool, \"华为云工具\", \"云工具\", \"工具\"",
                       "triggers":  [

                                    ],
Confidence
90% confidence
Finding
access credential

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal