Back to skill

Security audit

huawei-cloud-agentarts-otel-ingestion

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Huawei Cloud observability purpose, but it includes live cloud mutations and privileged internal API examples that need careful review before use.

Install only if you intend to configure Huawei Cloud AgentArts/APM observability. Use a sandbox or least-privilege Huawei Cloud project first, verify the internal deliverConfig API and te_admin role requirement with Huawei Cloud documentation or an administrator, keep IAM and business tokens out of logs and config files, review telemetry for prompts/PII/secrets before enabling export, and confirm cleanup steps for created businesses and forwarding configs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

text

Modify: `PUT /v2/trace/deliver-config` (body: `{id, deliver_otel_trace}`)
Delete: `DELETE /v2/trace/deliver-config/{id}?region=`

**4e. Configure application-side OTel SDK/Collector**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes forwarding traces, metrics, logs, and GenAI-related telemetry to remote Huawei Cloud endpoints, including attributes such as model names and token-usage metadata, without a clear privacy/data-classification warning. In AI-agent contexts, spans and logs can easily include prompts, tool arguments, user identifiers, and other sensitive business metadata, so omission of privacy guidance materially increases leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill tells users to record and reuse a returned business token and then shows it being placed into headers and configuration examples, but it does not explicitly call out that the token is a secret that must not be logged, committed, or embedded in files. In an observability/instrumentation workflow, tokens are especially prone to accidental exposure through shell history, sample configs, screenshots, and telemetry debugging output.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

ShowOpsTrace (official — verified):

bash
curl -X POST {AGENT_OPS_ENDPOINT}/v1/ops/observation/traces \
  -H "X-Auth-Token: {iam_token}" \
  -H "Content-Type: application/json" \
  -d '{"start_time": 1720000000000, "end_time": 1720600000000}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs users to download and immediately execute a remote shell installer via curl and bash without any integrity verification, version pinning, or warning about the risks of running remote code. If the hosting endpoint, transport path, or referenced script is compromised, users could execute arbitrary code on their systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template includes a live POST request that creates a remote tracing business but does not prominently warn that executing it will mutate production-like cloud resources. In an agent skill context, this omission can cause unintended resource creation, billing impact, or unauthorized changes if a user or agent runs the command without understanding its side effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The command sends authenticated data to an external cloud API endpoint, including a bearer-like token and request payload, which is an actual external transmission pattern. In this skill's observability ingestion context such transmission is expected, but it still carries security risk because secrets may be exposed and remote side effects occur if executed blindly.

Content

Scanner excerpt · templates/test-vars.json (reported line 15)May include surrounding context.

json
{
      "id": "TC-02",
      "name": "Create tracing business (API)",
      "command": "curl -s -o /dev/null -w '%{http_code}' -X POST {APM_ENDPOINT}/v1/apm2/openapi/tracing/business/create -H 'Content-Type: application/json' -H 'X-Auth-Token: {token}' -d '{\"name\":\"test-otel-business\",\"display_name\":\"test-app\",\"descp\":\"otel business\",\"cmdb_datasource_type\":\"AGENTRUN\"}'",
      "expected": "HTTP 200 or 201 response with business_id",
      "type": "api",
      "mutation": true,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command embeds an authentication token in a curl header and transmits it to an external endpoint without any accompanying privacy or credential-handling warning. In operational use, this increases the chance of token exposure through shell history, logs, agent traces, screenshots, or copied commands, leading to unauthorized API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This test case targets a user-provided internal endpoint and performs a POST mutation with privileged-looking headers such as x-apply-domain-id and x-apply-role-name, yet only notes manual verification without a strong safety warning. That combination makes the skill more dangerous because it could induce live configuration changes against sensitive infrastructure using user-supplied values that may not be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire report is written in Chinese, and the file does not indicate that language selection was user-configurable or that a Chinese-only locale is required. The policy for natural-language content requires either user opt-in or a clearly documented justification when a specific language/locale is enforced.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON manifest describes generic 'Test case templates' and a list of commands, but it does not define any explicit trigger phrases, scope boundaries, or exclusion conditions for when this skill/template should be invoked. In a manifest-style file, that ambiguity can make activation conditions overly broad if the surrounding system uses description text to select skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The variables fix the region and endpoints to cn-southwest-301, which imposes a locale/region choice in natural-language/config content without offering opt-in or documenting why that region is required. This can violate locale policy when a skill appears generally applicable but silently forces a specific regional setting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.