Back to skill

Security audit

huawei-cloud-ascendc-operator-performance-optim

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches AscendC operator optimization, but it ships unsafe local cleanup and permission guidance that users should review before installation.

Install only if you are comfortable letting the agent read and modify local AscendC operator projects and run profiling/build commands. Before using the scripts, review the chosen operator directory, back up any existing `OPPROF_*` results, and avoid following the `chmod 777 /tmp/opprof` advice; use a private user-owned profiling directory instead.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting.md:97
Finding

World-Writable Profiling Directory

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, line 97
Vulnerability Type: Insecure temporary-directory permissions
Risk Level: Medium

Vulnerable code snippet:

bash
# Use absolute path
msprof op --output=/tmp/opprof ./execute_op

# Check directory permissions
chmod 777 /tmp/opprof

Technical Analysis

The troubleshooting instructions recommend changing /tmp/opprof to mode 777. This grants every local user read, write, and traversal permissions over the profiling directory.

The command is presented as the remediation for profiling failures caused by insufficient permissions. If followed, it weakens access controls on profiling artifacts rather than creating a private directory owned by the user running the profiler.

Attack Path

  1. A user follows the troubleshooting procedure after msprof reports an output-directory permission problem.
  2. The user runs chmod 777 /tmp/opprof.
  3. Another local account gains read and write access to the profiling directory.
  4. That account can inspect, alter, replace, or delete profiling output generated in the directory.
  5. Subsequent analysis consumes attacker-modified artifacts, potentially producing falsified optimization conclusions.

Exploitation requires access through another local account on the same host and the vulnerable permission-setting instruction to have been applied.

Impact Assessment

The issue crosses a local-user trust boundary. An untrusted local user could tamper with or remove profiling artifacts and disrupt profiling operations. If the artifacts contain implementation or performance details, their world-readable permissions may also expose those details to other local users.

This does not grant elevated operating-system privileges by itself, and no evidence of malicious intent, credential theft, remote payload execution, persistence, or covert exfiltration was identified.

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to use mode 777.
  • Create a private, user-owned output directory with restrictive permissions:
    bash
    install -d -m 700 "$HOME/.local/state/ascend/opprof"
    msprof op --output="$HOME/.local/state/ascend/opprof" ./execute_op
    
  • If /tmp must be used, create a unique directory securely and restrict it to the current user:
    bash
    PROFILE_DIR="$(mktemp -d "${TMPDIR:-/tmp}/opprof.XXXXXX")"
    chmod 700 "$PROFILE_DIR"
    msprof op --output="$PROFILE_DIR" ./execute_op
    
  • Verify directory ownership before changing permissions, and never recursively weaken permissions on a path that may be controlled by another local user.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Using chmod 777 as a troubleshooting step is an abuse-prone parameter choice because it solves a permissions issue by disabling meaningful access control. In the context of performance tooling and build/run workflows, this is more dangerous because outputs in /tmp are commonly consumed by scripts and developer tools, increasing the chance of file replacement, race conditions, or symlink-based attacks in shared environments.

Content

Scanner excerpt · references/troubleshooting.md (reported line 97)May include surrounding context.

msprof op --output=/tmp/opprof ./execute_op

Check directory permissions

chmod 777 /tmp/opprof

text

### Issue: Profiling data incomplete

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes the standalone term "performance," which is overly broad and likely to match many unrelated user requests. This can cause accidental invocation of the skill outside its intended AscendC/NPU scope, leading to inappropriate guidance, tool exposure, or confusing task routing rather than direct code-execution risk.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

Although this is not explicitly a sudo command, the guidance encourages an unsafe permission change often associated with privileged troubleshooting and can lead users to weaken filesystem protections broadly. If followed on shared systems, it can let other local users alter files placed in the profiling directory or interfere with subsequent privileged or automated processes that consume those files.

Content

Scanner excerpt · references/troubleshooting.md (reported line 97)May include surrounding context.

msprof op --output=/tmp/opprof ./execute_op

Check directory permissions

chmod 777 /tmp/opprof

text

### Issue: Profiling data incomplete

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting guidance recommends chmod 777 /tmp/opprof, which makes the profiling directory world-readable, world-writable, and world-executable. In a shared or multi-user environment this can enable unauthorized tampering, symlink attacks, or disclosure/modification of profiling outputs, and the document gives no warning or safer alternative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script unconditionally runs rm -rf OPPROF_* in the provided operator directory, which can silently destroy existing profiling artifacts before the user has a chance to review or back them up. While the deletion is scoped to a filename pattern rather than arbitrary paths, it is still a real unsafe cleanup behavior because it performs destructive actions without confirmation, backup, or an explicit opt-in flag.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script unconditionally executes rm -rf OPPROF_* after changing into a user-supplied directory, with no confirmation, dry-run, or validation of what matches the glob. In a performance-optimization skill, users may run this in valuable build or profiling directories, so accidental deletion of profiling outputs or similarly named files/directories is plausible and can cause data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file states that the process should back up the original operator directory and generate output artifacts, which implies file creation and modification. Under the markdown-specific warning rule, the description should explicitly warn users that running the workflow will create backup directories and reports on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a markdown file, so vague-trigger review applies. The content provides general performance guidance but does not specify any invocation phrases, scope limits, or exclusion conditions, which can make a skill description overly broad if used as activation text or reference metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.