Back to skill

Security audit

huawei-cloud-agentorchard-find-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only marketplace search helper that runs a local Python script and contacts a disclosed public Huawei Cloud API, with no evidence of credential use, persistence, or automatic installation.

Install only if you are comfortable with the agent running the bundled Python search script and contacting Huawei Cloud's public AI Gallery endpoint. Treat results as marketplace links; any subscription or installation is a separate manual action on the Huawei Cloud page.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The implementation substantially matches the discovery/search/browse portions of the description: it loads skills from a public API, supports broad browsing for generic requests, and keyword search for more specific requests, then outputs matching skills and links to detail pages. However, the declared purpose explicitly includes 'install' and 'subscribe' capabilities, while the supplied code contains no installation, subscription, account interaction, mutation API calls, or other action beyond read-only retrieval and display. This is a material description-behavior mismatch because the description claims actionable marketplace operations that the code does not implement.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a Python script and explicitly requires network access to a remote API, but it declares no tool scope or permission boundaries. That means an agent may execute code with external connectivity without an explicit policy contract, reducing auditability and increasing the chance of unintended data egress or tool misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match generic requests like finding tools or extending functionality, which can cause the skill to activate unexpectedly. In an agent ecosystem, overbroad routing can redirect unrelated user requests into a workflow that executes code and sends user input to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that it uses a public remote API but does not clearly inform users that their search terms will be transmitted to an external Huawei Cloud endpoint. User queries may contain sensitive project names, internal initiatives, or other confidential terms, so undisclosed external transmission creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document title and all acceptance criteria are written exclusively in Chinese, and line L19 further frames language handling as asking the user to switch between Chinese and English rather than offering an explicit language preference policy. This can constitute a natural-language policy issue if the skill experience is effectively constrained to Chinese by default without clear user opt-in or an explicit language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. 'Expand Keywords CN-EN' indicates the skill enforces a Chinese-English language handling path, but the document does not mention user opt-in, alternative language choices, or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs the agent to execute a local Python script and to return its output directly, without any disclosure to the user that code will run on their behalf. This reduces transparency and can normalize silent tool execution, making it harder for users to understand when automation or subprocesses are being used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill documentation is written in Chinese, and the file does not provide an alternative language option or state that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a markdown file, so SQP-2 applies to missing warnings in the skill description. The flow explicitly shows 'Fetch All Skills from API', but the document contains no warning or disclosure that using the skill involves network calls to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing natural-language instructions only in Chinese, which can amount to a language policy violation if the skill is expected to be generally usable without requiring a specific language. There is no opt-in, alternative language option, or justification that the content is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring states the script purpose in Chinese, and all user-facing output strings throughout the script are hard-coded in Chinese. This creates a language/locale policy issue because the skill does not offer the user any language selection or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.