Back to skill

Security audit

huawei-cloud-ascend-command

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Huawei Ascend NPU management purpose, but it uses high-impact SSH/admin access with unsafe credential, host-verification, and permission guidance that should be reviewed before installation.

Install only if you intentionally need a high-privilege Ascend NPU administration skill. Prefer key-based SSH, strict known-host verification, non-root accounts with narrowly scoped sudo, and group or udev-based device permissions instead of chmod 666. Review mutating operations carefully before confirming firmware, vNPU, certificate, ECC, or fan changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/npu_client.py:52
Finding

SSH Host-Key Verification Is Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/npu_client.py, lines 52–59
Vulnerability Type: Improper SSH server authentication
Risk Level: High

Vulnerable Code

python
self._ssh_client = paramiko.SSHClient()
self._ssh_client.set_missing_host_key_policy(paramiko.AutoAddPolicy())
self._ssh_client.connect(
    hostname=self.ssh_host,
    port=self.ssh_port,
    username=self.ssh_user,
    password=self.ssh_password,
    timeout=30,
    look_for_keys=False,
    allow_agent=False
)

Technical Analysis

The SSH client applies paramiko.AutoAddPolicy(), which silently trusts a previously unknown host key. It does not load and enforce a trusted known-hosts entry or require the user to verify the server fingerprint.

Remote mode authenticates with the password supplied through the Skill's --password parameter. Consequently, an attacker who can intercept or redirect the connection can present an arbitrary SSH host key and be accepted as the intended NPU server. The subsequent password authentication and administrative command traffic then occur over a cryptographically protected connection to the attacker's server rather than the authorized endpoint.

The attacker-controlled point is the SSH endpoint visible to the client. Exploitation requires a network-positioning or redirection capability, such as traffic interception or compromise of the mechanism used to resolve or route to the selected host. Merely supplying normal user-selected connection parameters does not trigger the vulnerability.

Attack Path

  1. The user invokes the Skill in SSH mode with an authorized target host, username, and password.
  2. An attacker capable of intercepting or redirecting traffic causes the connection to reach an attacker-controlled SSH server.
  3. The malicious server presents a host key that is not already trusted by the client.
  4. AutoAddPolicy() accepts the unknown key without fingerprint verification.
  5. The client submits the configured SSH u ...[truncated 659 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace AutoAddPolicy with paramiko.RejectPolicy().
  • Load trusted host keys before connecting, for example through load_system_host_keys() and an application-specific known-hosts file.
  • Require explicit fingerprint verification and enrollment when connecting to a new host.
  • Treat host-key changes as hard failures and show both the expected and received fingerprints through a trusted user interface.
  • Do not silently retry a connection in a way that weakens host-key validation.
  • Prefer key-based user authentication where practical, while retaining strict server host-key verification regardless of the client authentication method.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/troubleshooting.md:86
Finding

Troubleshooting Guidance Grants World-Writable Access to NPU Device Nodes

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 86–91
Vulnerability Type: Excessive device permissions
Risk Level: Medium

Vulnerable Instructions

bash
# Add user to video group
usermod -aG video $USER

# Or set permissions (less secure)
chmod 666 /dev/davinci*

Technical Analysis

The troubleshooting guide presents chmod 666 /dev/davinci* as a solution for NPU device permission failures. This grants read and write access to every local user for every device node matching the wildcard.

Although the instruction labels the option as less secure, it does not restrict the affected devices, identify an authorized principal, or provide a temporary restoration step. If an administrator follows it, unrelated local accounts cross the intended NPU authorization boundary and receive direct access to the device interfaces.

The alternative group-based command is materially safer when group membership is tightly controlled. The world-writable fallback, however, defeats that access-control model.

Attack Path

  1. An administrator encounters a permission error while using the NPU Skill.
  2. The administrator follows the documented fallback and runs chmod 666 /dev/davinci* with sufficient privileges.
  3. All matching NPU device nodes become readable and writable by every local account.
  4. An otherwise unauthorized local user opens those device nodes through available drivers or NPU tooling.
  5. That user interacts with or disrupts NPU resources outside their assigned privileges.

Impact Assessment

The resulting privileges apply to all local users and all device nodes matched by /dev/davinci*. Depending on driver behavior and active workloads, unauthorized users may access NPU interfaces, interfere with jobs, consume or disrupt accelerator resources, expose device-managed workload data, or cause denial of service. The project does not demonstrate that this instruction is intended as a backdoor; it is an uns ...[truncated 30 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the chmod 666 /dev/davinci* fallback.
  • Use a dedicated NPU access group whose membership is limited to authorized operators.
  • Configure persistent udev rules that assign the required device nodes to that group with mode 0660.
  • Where group access is unsuitable, apply narrowly scoped ACLs to specific users and device nodes.
  • Avoid wildcard permission changes unless the exact matched device set has first been reviewed.
  • Document how to verify and restore secure ownership and modes after troubleshooting.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (29)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list is very broad and includes generic terms like 'compute', 'health', 'memory', 'power', and 'temperature', which can cause the skill to activate in unrelated contexts. Because this skill can execute local or remote administrative commands and accept SSH credentials, unintended activation materially increases the chance of risky command execution against the wrong target or with insufficient user awareness.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a true dangerous-parameter issue because chmod 666 /dev/davinci* applies an overly permissive mode to device files using a wildcard. In the context of a skill that manages NPUs locally and over SSH, recommending such a command materially increases the chance that operators weaken host security and expose hardware control interfaces to unauthorized users or processes.

Content

Scanner excerpt · references/troubleshooting.md (reported line 91)May include surrounding context.

usermod -aG video $USER

Or set permissions (less secure)

chmod 666 /dev/davinci*

text

## 3. Command Execution Issues

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

execute_batch accepts arbitrary command strings and concatenates them into a single shell command using && and echo, then sends that string to _execute. In SSH mode this reaches paramiko.exec_command, which executes via the remote shell, allowing arbitrary remote command execution well beyond the skill's stated NPU-management scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and overview emphasize remote SSH execution with host, user, and password parameters but do not prominently warn that the skill may run commands on remote systems using supplied credentials. In a skill that supports firmware upgrade, configuration changes, virtualization, and certificate operations, lack of an explicit warning reduces informed consent and can lead users or orchestrators to invoke sensitive remote actions without appreciating the security implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The verification commands are described in broad, natural-language forms such as temperature, memory, power, utilization, and health-related phrases, which can overlap with ordinary user requests. In a skill that can perform device management and remote operations, loose command scoping increases the risk of unintended invocation, data disclosure about infrastructure state, or accidental transition into privileged workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Remote-access and virtualization commands like listing, creating, or deleting vNPUs are high-impact administrative actions, yet the acceptance criteria describe them with minimal scoping. In the context of a skill that supports SSH and infrastructure control, insufficiently constrained activation phrases could lead to accidental execution of privileged remote or virtualization operations affecting availability and isolation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states at L106 that the paramiko library must be installed for SSH functionality, but later states at L115 that there are no external dependencies beyond the standard library. These two statements directly contradict each other in the skill's documentation, creating an intent/documentation divergence about required capabilities and deployment requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The listed triggers "Certificate status" and "Certificate info" are short, generic phrases without scope restrictions, negative examples, or invocation context. In a markdown skill reference, this ambiguity can cause the skill to match ordinary certificate-related discussion rather than an explicit request to run the associated command.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase "Install certificate" is broad enough to match common certificate-management requests outside the intended Ascend NPU context. In a skill that includes sensitive state-changing operations, ambiguous triggering can lead to unintended invocation and accidental certificate installation on managed hardware, especially if used in automated agent routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase "Update certificate" is ambiguous because it could refer to renewal, replacement, trust-store changes, or unrelated certificate maintenance. In this skill, where certificate actions are sensitive and state changing, such ambiguity increases the risk of the wrong command being selected and executed on production NPU devices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language triggers in this section include very generic terms such as 'Temperature', 'Usage', 'ECC', and 'PCIe', which can easily match unrelated user requests. In an agent skill that can perform hardware management actions or disclose device state, overly broad triggering increases the chance of unintended invocation and execution against NPU infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language trigger "Upgrade firmware" is broad for a destructive operation that changes device state, and the file does not show strong contextual gating beyond a note that confirmation is required. In an agent skill, broad triggers for firmware modification increase the chance of accidental invocation or prompt-collision with benign user requests about firmware information rather than upgrade execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rollback trigger "Rollback firmware" is especially risky because it maps a short natural-language phrase directly to a disruptive administrative action that can alter device state or availability. Without stronger contextual constraints, a user asking about rollback options or recovery guidance could unintentionally trigger an actual rollback command.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/certificate-management.md (reported line 179)May include surrounding context.

md
**Solution:**
1. Verify firmware file integrity
2. Run as root
3. Stop all NPU processes
4. Free up disk space

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/firmware-upgrade.md (reported line 151)May include surrounding context.

md
**Solution:**
1. Verify firmware file integrity
2. Run as root
3. Stop all NPU processes
4. Free up disk space

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting.md (reported line 40)May include surrounding context.

bash
# On target machine
systemctl start sshd
systemctl enable sshd

2. NPU-SMI Issues

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The documentation suggests chmod 666 /dev/davinci*, which makes NPU device nodes world-readable and world-writable. On systems managing accelerator hardware, this can allow any local user or process to interact with device interfaces, potentially leading to unauthorized access, interference with workloads, data exposure, or abuse of privileged hardware capabilities.

Content

Scanner excerpt · references/troubleshooting.md (reported line 91)May include surrounding context.

usermod -aG video $USER

Or set permissions (less secure)

chmod 666 /dev/davinci*

text

## 3. Command Execution Issues

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/troubleshooting.md (reported line 138)May include surrounding context.

md
**Expected behavior:** Single device ~2 seconds, multi-device should be parallel

**Solution:** The skill automatically runs multi-device tests in parallel

## 5. Compatibility Issues

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation shows SSH remote examples using --user root --password xxx directly on the command line. Even though the password is a placeholder, this normalizes an unsafe usage pattern because real operators may substitute production credentials, which can then be exposed via shell history, process listings, logs, screenshots, or CI output. In a skill specifically designed for remote infrastructure management, this is more dangerous because it encourages insecure handling of privileged credentials for high-impact administrative access.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The troubleshooting guidance explicitly suggests running commands as root, which normalizes privileged execution for virtualization management. In a skill that can issue hardware-management commands locally or over SSH, encouraging root use expands blast radius: a misrouted, malformed, or abused command could modify device state, destroy vNPU data, or affect the host more severely under elevated privileges.

Content

Scanner excerpt · references/virtualization.md (reported line 179)May include surrounding context.

md
**Solution:**
1. Check resource allocation
2. Update firmware
3. Run as root

### Issue: vNPU performance slow

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/executor.py (reported line 561)May include surrounding context.

python
if self.client.ssh_host:
            output = self.client._execute(cmd)
        else:
            result = subprocess.run(shlex.split(cmd), shell=False, capture_output=True, text=True, timeout=120)
            output = result.stdout

        return self._parse_flops_output(output, npu_id, precision)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/executor.py (reported line 612)May include surrounding context.

python
if self.client.ssh_host:
            output = self.client._execute(cmd)
        else:
            result = subprocess.run(shlex.split(cmd), shell=False, capture_output=True, text=True, timeout=120)
            output = result.stdout

        return self._parse_flops_output(output, npu_id, precision)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill supports SSH remote execution using a plaintext password argument, but the interface shown in this file provides no explicit warning that credentials will be transmitted to a remote host and that commands may be executed against another system. In a high-risk administrative skill that can perform firmware changes, virtualization operations, and certificate management, lack of user-facing disclosure increases the chance of unsafe credential handling and unintended remote administrative actions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/npu_client.py (reported line 101)May include surrounding context.

python
else:
            # Local direct mode: execute npu-smi directly
            import shlex
            result = subprocess.run(
                shlex.split(command), shell=False,
                capture_output=True, text=True, timeout=60
            )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The client exposes state-changing and potentially destructive operations such as ECC changes, fan control, vNPU creation/destruction, certificate threshold changes, and firmware upload/activation with no confirmation, safety interlocks, or authorization checks. In an agent skill context, that increases the chance of accidental or unauthorized hardware disruption, degraded reliability, or bricking devices during remote administration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.