Back to skill

Security audit

huawei-cloud-icp-process-guidance

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a Huawei Cloud ICP filing Q&A helper, but its optional search fallback asks users to install and use an external Agent Reach/Exa toolchain that is broader than the bundled knowledge-base purpose.

Review the Agent Reach dependency before installing. Use the skill's bundled knowledge base when possible, avoid queries containing personal filing data, and treat network-search results as supplemental unless they come from Huawei Cloud or official MIIT sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The file explicitly expands behavior from a local ICP knowledge-base Q&A skill into live web searching whenever the KB is empty, stale, or the user asks for recent information. This changes the trust boundary and can expose the agent to unvetted external content, prompt-injection in search results, and answers that exceed the skill’s declared scope.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation authorizes use of an external tool (`mcporter` calling Exa) without clear declaration in the visible skill metadata, effectively granting undeclared networked capability. Undeclared tool use is dangerous because it can bypass expected operator controls, leak user queries to third parties, and import untrusted data into the model’s reasoning path.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.