Back to skill

Security audit

huawei-cloud-ascend-small-model-migrate

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Ascend NPU migration guide, but it exposes a root SSH credential for a named server and repeatedly directs root access.

Review before installing. Do not use the published root credential; treat it as exposed, rotate it if real, and require users to supply their own least-privilege SSH credentials through a secret manager or interactive approval. Run package installs and Docker changes only in an isolated container or test host, and narrow use to explicit Ascend/NPU migration tasks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:362
Finding

Hardcoded Root SSH Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 362
Vulnerability Type: Hardcoded privileged credential
Risk Level: High

Vulnerable Snippet

markdown
- **Server**: ascend-server-01:22 (root/Hhuawei@smb)

Technical Analysis

The Skill embeds a plaintext SSH username and password for a root account in distributable documentation. This exposes the credential to every user or process that can read the Skill package.

The project’s documented workflow repeatedly connects to ascend-server-01 as root, including commands in references/verification-method.md and references/troubleshooting.md. If the host is reachable and password authentication is enabled, the exposed credential may permit direct privileged access without an additional authorization boundary.

No evidence indicates that the Skill itself transmits this credential to an unrelated party or uses it as part of a covert attack. This is therefore a vulnerable secret-management practice rather than confirmed credential theft or malicious behavior.

Attack Path

  1. An unauthorized party obtains or reads the distributed Skill package.
  2. The party extracts the hostname, SSH port, root username, and plaintext password from SKILL.md.
  3. The party establishes network access to ascend-server-01:22.
  4. If SSH password authentication remains enabled and the credential is valid, the party authenticates as root.
  5. The resulting root session can be used to inspect or modify the server, its containers, model files, NPU workloads, and locally accessible secrets.

Successful exploitation depends on the documented server being reachable and accepting the exposed credential.

Impact Assessment

Successful authentication grants root-level administrative privileges on the target server. The attacker could read or alter model and profiling data, modify or stop containers and NPU workloads, access locally stored credentials, install software, or disrupt migration operatio ...[truncated 108 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hostname/password combination from all tracked files and repository history.
  2. Rotate the exposed password immediately; removal from the current file does not invalidate previously distributed copies.
  3. Disable direct root SSH login and password-based SSH authentication where operationally possible.
  4. Provision individual, least-privilege administrative accounts using managed SSH keys or short-lived certificates.
  5. Store required secrets in an approved secret manager or deployment-time environment rather than Skill documentation.
  6. Replace the documentation value with a nonfunctional placeholder, such as:
markdown
- **Server**: `<user-provided-host>:<port>` (credentials supplied through an approved secret manager)
  1. Review authentication logs for use of the exposed root credential and investigate any unauthorized access.
  2. Add secret scanning to development and release workflows to prevent credentials from being committed again.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a broad end-to-end Ascend NPU migration workflow for small vision models, including verification, profiling, and optimization. The supplied code is much narrower: it analyzes a model identifier/path, tries to infer architecture type using transformers config metadata or a YOLO keyword check, and recommends a migration path. This is only a small subset of the declared 'model structure analysis' functionality and does not implement the rest of the advertised workflow. Additionally, the code explicitly handles decoder-only LLMs and VLMs, which is outside the declared primary scope of encoder-only/small vision detection and segmentation models. Therefore the description materially overstates and partly mischaracterizes the actual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds a root username/password for a specific host, which is a direct secret exposure and enables privileged remote access if the credential is valid. In the context of an agent skill with allowed SSH and Docker tooling, this is especially dangerous because an agent or downstream user could immediately use the credential to access infrastructure, exfiltrate data, modify systems, or pivot further.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation exposes privileged host access details and credentials without any warning, approval checkpoint, or safety boundary, which normalizes direct use of sensitive infrastructure access. In this skill's context, that is more dangerous because the advertised workflow encourages users or agents to connect to a named server and container for execution, making accidental or unauthorized access far more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is excessively broad, including common terms like 'migrate', 'adapt', 'YOLO', and 'NPU', which can cause the skill to activate during ordinary technical discussions unrelated to this workflow. Because the skill also references privileged infrastructure and operational commands, over-triggering increases the chance that an agent will surface sensitive instructions or attempt inappropriate high-risk actions in the wrong context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 64)May include surrounding context.

Error: Assume NPU is available

python
# Without checking availability
model = model.to('npu:0')  # May fail silently

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ResNet example uses getattr(models, model_name)(pretrained=True), which can trigger an implicit download of pretrained weights from external sources at runtime. That network-fetch capability is not disclosed in the surrounding reference text, so running the example in restricted or sensitive environments can cause unexpected outbound connections, dependency on unpinned remote artifacts, and supply-chain exposure if external sources are tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 144)May include surrounding context.

md
msprof op --output=./profiling_data python3 inference.py

# Check permissions
chmod 755 /path/to/output_dir

# Run with full path
cd /path/to/model && msprof op --output=./profiling_data python3 inference.py

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill for migrating encoder-only small vision models such as ResNet, YOLO, and UNet to Ascend NPU. This code classifies and recommends migration routes for decoder-only LLMs, encoder-decoder models, and vision-language models, which materially exceeds that stated scope rather than merely implementing the advertised vision-model workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The troubleshooting guidance tells users to uninstall and reinstall torch_npu directly in the active Python environment without warning that this may alter or break a shared system, container, or production runtime. While not an exploit by itself, it can cause accidental disruption, dependency drift, or loss of a working state, especially in migration workflows where environment compatibility is critical.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The top-level and function docstrings describe the script as analyzing model structure and judging msmodelslim compatibility. In practice, the code goes further by assigning broader migration-route recommendations such as 'torch_npu straightconnectMigration' for multiple unsupported architectures, which diverges from the narrower documented intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.