Back to skill

Security audit

huawei-cloud-ascend-remote-connect

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed SSH remote administration skill, but its safety promises are weakened by bypassable confirmations, disabled SSH host verification, and broad privileged actions.

Review before installing. Use only with hosts you control, avoid root/password login where possible, verify SSH host keys outside the skill, and assume raw/one-shot commands can run without the promised confirmation prompts. Treat SSH key listing and key generation as sensitive administrative actions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:119
Finding

Destructive-command confirmation can be bypassed through one-shot execution

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py:119-146
Vulnerability Type: Missing centralized authorization and confirmation enforcement
Risk Level: High

Complete Code Snippet

python
def run_one_shot_fast(host, port, user, password, command, raw=False):
    """Fast mode: Use SSH ControlMaster to reuse connection
    First time ~1.5s, subsequent ~0.2s
    When raw=True, skip natural language parsing and execute raw command directly"""
    ctrl_path = _ensure_connection(host, port, user, password)
    if not ctrl_path:
        return run_one_shot_paramiko(host, port, user, password, command, raw=raw)

    # Raw mode: execute directly, bypass NL routing
    if raw:
        result = subprocess.run(
            ['ssh', '-o', f'ControlPath={ctrl_path}', '-o', 'ControlMaster=auto',
             '-o', 'BatchMode=yes', '-p', str(port), f'{user}@{host}', command],
            capture_output=True, text=True, timeout=60
        )
        if result.returncode == 0:
            if result.stdout.strip():
                print(result.stdout.strip())
        else:
            if result.stderr.strip():
                print(f"❌ Error (exit {result.returncode}): {result.stderr.strip()}")
            elif result.stdout.strip():
                print(result.stdout.strip())
        return result.returncode

    # Determine if command is natural language
    # Strategy: if it looks like a shell command, execute directly; otherwise route to NL
    is_nl = not _is_shell_command(command)

    if is_nl:
        # Natural language goes through executor (requires paramiko connection)
        executor = CommandExecutor()
        connect_text = f"SSH connect {host} port {port} user {user} password {password}"
        executor.handle_command(connect_text)
        result = executor.handle_command(command)
        print(result)
        executor.session_manager.close_all_sessions()
        return 0
    else:
        # Direct shell command goes through fast mode

...[truncated 3255 chars]
Remediation
View remediation

Remediation Suggestions

  1. Route every remote command, including one-shot, fast, fallback, and raw modes, through one centralized authorization function.
  2. Do not allow --raw to bypass validation. If raw execution is required, apply the same blocked-command and confirmation policy before opening the SSH execution channel.
  3. Require a non-replayable confirmation token bound to the exact command, target host, username, and expiration time.
  4. Default unrecognized commands to rejection or explicit confirmation instead of CommandType.ALLOWED.
  5. Parse shell command structure rather than relying only on anchored regular expressions. Account for wrappers, command substitution, pipelines, separators, redirections, and shell interpreters.
  6. Revalidate the exact final command immediately before execution so that command transformations cannot occur after confirmation.
  7. Add tests covering destructive commands through all entry paths, including --raw, shell-looking --command values, compound commands, and Paramiko fallback behavior.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:37
Finding

SSH host identity verification is disabled in both connection implementations

Content
View full analysis

Vulnerability Details

File Locations: scripts/main.py:37-40; scripts/ssh_client.py:41-43
Vulnerability Type: Improper SSH host-key verification
Risk Level: High

Complete Code Snippets

OpenSSH connection options in scripts/main.py:

python
ssh_opts = [
    '-o', 'StrictHostKeyChecking=no',
    '-o', 'UserKnownHostsFile=/dev/null',
    '-o', f'ControlPath={ctrl_path}',
    '-o', 'ControlMaster=auto',
    '-o', 'ControlPersist=10m',   # Auto close after 10 minutes idle
    '-o', 'ServerAliveInterval=30',
    '-o', 'ServerAliveCountMax=3',
    '-p', str(port),
]

Paramiko connection setup in scripts/ssh_client.py:

python
def connect(self) -> bool:
    try:
        self.client = paramiko.SSHClient()
        self.client.set_missing_host_key_policy(paramiko.AutoAddPolicy())

        connect_kwargs: Dict[str, Any] = {
            'hostname': self.conn_info.host,
            'port': self.conn_info.port,
            'username': self.conn_info.username,
            'timeout': self.conn_info.timeout,
            'look_for_keys': False,
            'allow_agent': False,
        }

Technical Analysis

The OpenSSH path disables strict host-key checking and discards persistent host-key records by directing them to /dev/null. The Paramiko path similarly accepts previously unknown host keys through AutoAddPolicy().

A server fingerprint is calculated only after Paramiko has accepted and authenticated the connection. Reporting a fingerprint after trust has already been granted does not authenticate the endpoint or prevent interception.

This removes SSH’s endpoint-authentication property. An attacker able to intercept, redirect, or spoof network traffic can present an arbitrary SSH host key, and the Skill will accept that endpoint without comparing it to a trusted key or requiring explicit enrollment.

Attack Path

  1. The user selects a legitimate SSH host and supplies a username and password.
  2. A network-positioned attack ...[truncated 1169 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove StrictHostKeyChecking=no and UserKnownHostsFile=/dev/null.
  2. Use a protected, persistent known_hosts file and enable strict host-key verification.
  3. Load trusted host keys in Paramiko and use RejectPolicy() for unknown or changed keys.
  4. For first use, require explicit fingerprint enrollment through a trusted out-of-band channel or an explicit user confirmation that displays the expected fingerprint.
  5. Bind trusted keys to the exact host and port, and fail closed if a previously trusted key changes.
  6. Perform host verification before transmitting passwords or executing commands.
  7. Add automated tests proving that unknown and changed host keys are rejected in both OpenSSH and Paramiko paths.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (63)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document claims temporary in-memory credentials and mandatory confirmation for sensitive actions, but also describes connection pooling, retained sessions, key-based auth, and generic command execution without any visible enforcement mechanism for confirmations. This creates a trust and control gap: operators may believe destructive actions are guarded when the effective behavior is persistent remote administration infrastructure with insufficiently demonstrated safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document claims temporary in-memory credentials and mandatory confirmation for sensitive actions, but also describes connection pooling, retained sessions, key-based auth, and generic command execution without any visible enforcement mechanism for confirmations. This creates a trust and control gap: operators may believe destructive actions are guarded when the effective behavior is persistent remote administration infrastructure with insufficiently demonstrated safeguards.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/iam-policies.md (reported line 17)May include surrounding context.

md
|------------|-------------|
| SSH login | Access to SSH service (port 22) |
| Command execution | Execute basic shell commands |
| sudo privileges | For system management operations |

### Minimum Required Privileges

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/iam-policies.md (reported line 93)May include surrounding context.

md
|------------|-------------|
| SSH login | Access to SSH service (port 22) |
| Command execution | Execute basic shell commands |
| sudo privileges | For system management operations |

### Minimum Required Privileges

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/iam-policies.md (reported line 94)May include surrounding context.

md
|------------|-------------|
| SSH login | Access to SSH service (port 22) |
| Command execution | Execute basic shell commands |
| sudo privileges | For system management operations |

### Minimum Required Privileges

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/iam-policies.md (reported line 96)May include surrounding context.

md
|------------|-------------|
| SSH login | Access to SSH service (port 22) |
| Command execution | Execute basic shell commands |
| sudo privileges | For system management operations |

### Minimum Required Privileges

Chaining Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The matrix states container management may be done via sudo or docker group, and Docker group access is commonly equivalent to root because it allows mounting the host filesystem, running privileged containers, or escaping intended isolation boundaries. In a skill centered on remote connectivity and command execution, this meaningfully enables privilege chaining from container administration to full host compromise.

Content

Scanner excerpt · references/iam-policies.md (reported line 95)May include surrounding context.

md
| View system info | Regular user |
| Disk management | sudo |
| System updates | sudo |
| Container management | sudo or docker group |
| User management | sudo |

## Audit Logging

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/verification-method.md (reported line 72)May include surrounding context.

Step 6: Sensitive Operation Confirmation Test

text
Delete /tmp/test.txt

Expected Output:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/verification-method.md (reported line 77)May include surrounding context.

Expected Output:

text
⚠️⚠️ High-risk operation: Will delete /tmp/test.txt

Please reply "Confirm" or "Cancel"

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The validator is fail-open: after checking a small denylist and a prefix allowlist, it returns ALLOWED for every unmatched command. In a remote SSH execution skill, this means an attacker or careless user can run arbitrary shell commands simply by choosing commands not covered by the regexes or prefixes, bypassing the intended safety model and any confirmation gating.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'mcp' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/executor.py (reported line 242)May include surrounding context.

python
elif action == 'users':
                    return self._exec_simple('online users', 'who; echo; echo "=== recent logins ==="; last -5')
                elif action == 'crontab':
                    return self._exec_simple('scheduled tasks', 'echo "=== root crontab ==="; crontab -l 2>/dev/null || echo "none"; echo; for user in $(cut -d: -f1 /etc/passwd | head -10); do crontab -u $user -l 2>/dev/null && echo "[$user]:" && crontab -u $user -l 2>/dev/null; done 2>/dev/null | head -50')
                elif action == 'processes':
                    return self._exec_simple('process list', 'ps aux --sort=-%cpu | head -20')
                elif action == 'env':

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/executor.py (reported line 430)May include surrounding context.

python
elif action == 'users':
                    return self._exec_simple('online users', 'who; echo; echo "=== recent logins ==="; last -5')
                elif action == 'crontab':
                    return self._exec_simple('scheduled tasks', 'echo "=== root crontab ==="; crontab -l 2>/dev/null || echo "none"; echo; for user in $(cut -d: -f1 /etc/passwd | head -10); do crontab -u $user -l 2>/dev/null && echo "[$user]:" && crontab -u $user -l 2>/dev/null; done 2>/dev/null | head -50')
                elif action == 'processes':
                    return self._exec_simple('process list', 'ps aux --sort=-%cpu | head -20')
                elif action == 'env':

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill reads and returns the contents of authorized_keys files for root and users without any warning or masking. While public keys are not passwords, they are sensitive authentication metadata that reveal trusted principals and enable account targeting and infrastructure mapping.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Reading /root/.ssh/authorized_keys and users' authorized_keys exposes authentication relationships and trusted access paths on the host. In this remote administration context, that materially aids reconnaissance and credential-targeting against privileged accounts.

Content

Scanner excerpt · scripts/executor.py (reported line 426)May include surrounding context.

python
elif action == 'ssh_config':
                    return self._exec_simple('SSH config', 'grep -v "^#" /etc/ssh/sshd_config 2>/dev/null | grep -v "^$"')
                elif action == 'ssh_keys':
                    return self._exec_simple('SSH keys', 'echo "=== root authorized_keys ==="; cat /root/.ssh/authorized_keys 2>/dev/null || echo "none"; for user in $(ls /home/ 2>/dev/null | head -5); do echo; echo "=== $user ==="; cat /home/$user/.ssh/authorized_keys 2>/dev/null || echo "none"; done')
                elif action == 'security_check':
                    return self._exec_simple('security check', 'echo "=== open ports ==="; ss -tlnp 2>/dev/null | head -20; echo; echo "=== firewall ==="; iptables -L -n 2>/dev/null | head -10 || echo "none"; echo; echo "=== SSH config ==="; grep -E "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/ssh/sshd_config 2>/dev/null; echo; echo "=== failed logins (recent 5) ==="; lastb -10 2>/dev/null | head -5 || echo "none"')
                elif action == 'system_users':

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
90% confidence
Finding

Although the code does not inject keys, it exposes existing authorized_keys contents for privileged and user accounts. In this context, that dual-use capability supports mapping trusted access paths and can facilitate follow-on compromise, making it materially dangerous even if not overtly malicious.

Content

Scanner excerpt · scripts/executor.py (reported line 426)May include surrounding context.

python
return self._exec_simple('failed logins', 'lastb -20 2>/dev/null || echo "No failed login records or permission denied"')
                elif action == 'ssh_config':
                    return self._exec_simple('SSH config', 'grep -v "^#" /etc/ssh/sshd_config 2>/dev/null | grep -v "^$"')
                elif action == 'ssh_keys':
                    return self._exec_simple('SSH keys', 'echo "=== root authorized_keys ==="; cat /root/.ssh/authorized_keys 2>/dev/null || echo "none"; for user in $(ls /home/ 2>/dev/null | head -5); do echo; echo "=== $user ==="; cat /home/$user/.ssh/authorized_keys 2>/dev/null || echo "none"; done')
                elif action == 'security_check':
                    return self._exec_simple('security check', 'echo "=== open ports ==="; ss -tlnp 2>/dev/null | head -20; echo; echo "=== firewall ==="; iptables -L -n 2>/dev/null | head -10 || echo "none"; echo; echo "=== SSH config ==="; grep -E "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/executor.py (reported line 432)May include surrounding context.

python
hd_config 2>/dev/null; echo; echo "=== failed logins (recent 5) ==="; lastb -10 2>/dev/null | head -5 || echo "none"')
                elif action == 'system_users':
                    return self._exec_simple('system users', 'cat /etc/passwd | grep -v nologin | grep -v false | grep -v sync')
                elif action == 'suid_check':
                    return self._exec_simple('SUID files', 'find / -perm -4000 -type f 2>/dev/null | head -30')

        # Key generation (sensitive)
        if 'generate key' in text or 'create key' in text:
            self.pending_confirmation = 'ssh-keygen -t ed25519 -f /root/.ssh/id_ed25519 -N "" && cat /root/.ssh/id_ed25519.pub'
            return '⚠️ Will generate new ED25519 key pair\n\nPlease reply "confirm" or "cancel"'

        return None

    # ========== Log Module ==========

    def _handle_log_nl(self, text: str) -> Optional[str]:
        """Log-relatednatural language"""
        if not self.session_manager.active_session:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill can generate a new root SSH keypair on the remote host and reveal the public key to the caller. In a remote-connect/admin skill, creating new authentication material on the target can facilitate persistence or unauthorized future access if misused.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Generating /root/.ssh/id_ed25519 creates new root authentication material, which can be used to maintain or expand access to the host. In a remote shell skill, this crosses from observation into persistence-enabling credential manipulation.

Content

Scanner excerpt · scripts/executor.py (reported line 436)May include surrounding context.

python
# Key generation (sensitive)
        if 'generate key' in text or 'create key' in text:
            self.pending_confirmation = 'ssh-keygen -t ed25519 -f /root/.ssh/id_ed25519 -N "" && cat /root/.ssh/id_ed25519.pub'
            return '⚠️ Will generate new ED25519 key pair\n\nPlease reply "confirm" or "cancel"'

        return None

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest promises that sensitive operations require user confirmation, yet one-shot and raw modes execute commands immediately once arguments are provided. This is a genuine safety-design violation that undermines user expectations and can lead to silent destructive remote administration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The help text states that sensitive operations require confirmation and high-risk commands are blocked, but the code contains raw and direct execution paths that perform unrestricted remote command execution. This mismatch is dangerous because users may rely on stated safety guarantees that do not actually exist, increasing the chance of accidental destructive actions.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger words are broad terms such as SSH, remote, and NPU, which can cause the skill to activate in contexts far beyond the user's intent. For a skill that handles credentials and remote command execution, accidental invocation materially increases the chance of unintended access, command routing, or sensitive-operation prompting in unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The usage examples present broad natural-language requests that map to powerful remote actions without clear scope boundaries or an explicit arming step. In a remote administration skill, this increases the risk that vague user text is interpreted as authorization to execute sensitive commands on a live server.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
**Minimum required permissions on target server:**
- SSH access (port 22 or custom)
- Sudo privileges for system management operations

## Core Workflow

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
references/verification-method.md:25

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:145