Back to skill

Security audit

huawei-cloud-agentarts-obs-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Huawei Cloud observability troubleshooting guide, but it includes cloud resource creation steps inside the diagnostic flow without clear approval or cost warnings.

Install only if you are comfortable giving the agent Huawei Cloud observability and IAM read access, and do not let it run CreateBusiness, CreatePromInstance, or other subscription/resource-creation steps unless an authorized user explicitly approves the change and cost impact. Replace cn-north-4 with the correct region for your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a diagnosis workflow, but it includes write operations that create APM and AOM resources during troubleshooting. That breaks the expected read-only safety boundary for a diagnostic skill and can cause unintended infrastructure changes, billing impact, and configuration drift if an agent or user follows it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented diagnosis steps instruct users to create cloud resources without prominently warning that these actions modify the environment and may incur charges. In an agent skill context, omission of side-effect and cost warnings increases the chance of unsafe or unauthorized changes being made under the guise of troubleshooting.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

text
4. **agent-ops query side** (API only — not in KooCLI):
   ```bash
   curl -X POST ${AGENT_OPS_ENDPOINT}/v1/ops/observation/traces \
     -H "Authorization: Bearer ${IAM_TOKEN}" \
     -H "Content-Type: application/json" \
     -d '{"start_time": 1720000000000, "end_time": 1720600000000}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill focused on diagnosing missing metrics, logs, traces, sessions, subscription metadata, data pipelines, query parameters, and authentication in the observability stack. Including generic IAM policy listing and authorization schema discovery adds a broader identity-enumeration capability that is not clearly justified by the stated diagnosis purpose, especially in a static test template file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
54% confidence
Finding

The document requires verification of timestamp formatting and region consistency, which may imply fixed locale or regional constraints in diagnostic handling. However, the file does not clearly state whether these constraints are user-selectable or justified as part of a region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The report template fixes the Region field to cn-north-4, which is a locale/region constraint expressed in natural language content. Because the template does not say this is optional, user-selected, or limited to a region-specific workflow, it can steer users toward a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The command examples all include --cli-region=cn-north-4, which imposes a specific locale/region in the template content. The file does not offer an alternative region selection or explain that the commands are valid only for a region-specific environment, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example command fixes --cli-region=cn-north-4, and the same pattern appears elsewhere in the file. For a general IAM policy reference, this imposes a locale/region-specific default without documenting that the skill is intended only for that region or giving users an opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The command example mandates --cli-region=cn-north-4 with no note that the file is region-scoped. This can violate locale/region policy expectations when the skill appears to be generic but only demonstrates one fixed region.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This example again uses --cli-region=cn-north-4 as a fixed region while the surrounding documentation does not explain a region limitation. A generic reference should either justify the regional constraint or allow user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The system policy verification command fixes the CLI region to cn-north-4 without any stated justification or opt-in. This is a natural-language/configuration policy issue because the file otherwise reads like a general IAM reference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple command templates force --cli-region=cn-north-4, which is a locale-specific constraint embedded throughout the file. Because the file does not indicate that this region is optional, user-selectable, or justified by a region-specific purpose, it risks violating language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.