Back to skill

Security audit

huawei-cloud-billing-scout

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a read-only Huawei Cloud billing helper, but its setup references include unsafe installer patterns and some off-scope cloud CLI guidance that users should review before installing.

Install only if you are comfortable letting the agent use your current hcloud profile for read-only Huawei Cloud billing evidence. Before using it, verify the active account/profile, grant only BSS read-only permissions where possible, avoid running the one-line remote installer or '-y' examples without independent verification, and treat the off-scope KooCLI/ECS/setup commands as general documentation rather than skill-authorized actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (40)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
`SKILL.md` defines behavior; `semantic/catalog.yml` defines entry points and required context; `semantic/billing-ontology.yml` defines facts, grains, money_basi

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document describes KooCLI as a general tool for managing 100+ cloud services, which materially exceeds the skill's declared Huawei Cloud BSS billing-only scope. In an agent context, broad operational guidance can enable off-scope infrastructure actions and increases the chance the skill is used to perform unintended cloud administration tasks.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This is a classic fetch-and-execute pattern: downloading a remote script and immediately running it. It is dangerous because users or agents execute code they have not independently verified, creating a direct supply-chain compromise path.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The non-interactive fetch-and-execute variant is even riskier because it removes confirmation barriers while still executing unverified remote code. In an agent setting, this materially raises the likelihood of silent environment modification or compromise.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The Dockerfile embeds a remote-script download and execution during image build, making every build dependent on mutable external code. This undermines reproducibility and allows upstream script changes or compromise to silently alter produced images.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 105)May include surrounding context.

Custom Image

dockerfile
FROM ubuntu:latest
RUN apt-get update -y && apt-get install curl -y
RUN curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y
WORKDIR /workspace
ENTRYPOINT ["/usr/local/bin/hcloud"]

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example hcloud ECS NovaListServers is a non-billing resource-management operation that directly conflicts with the manifest's billing-only scope. In a tool-using agent, this kind of example can normalize or trigger cloud inventory and operational access outside intended boundaries.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

This troubleshooting path again recommends fetching and executing an external installer script. Repeating this pattern normalizes unsafe installation behavior and expands the attack surface for supply-chain or MITM-style compromise if trust assumptions fail.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 160)May include surrounding context.

sudo bash ./hcloud_install.sh

Or install to user directory

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -d ~/.local/bin

text

#### Command Not Found

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

Using the same fetch-and-execute pattern for updates is particularly risky because users may trust update flows more and run them frequently. A compromised upstream script could then gain repeated opportunities to execute arbitrary code.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 205)May include surrounding context.

hcloud update

Or reinstall latest version

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Uninstall KooCLI

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

sudo rm -f /usr/local/bin/hcloud is a privileged destructive command that deletes a system binary. In documentation for an agent skill that is supposed to avoid delete actions, including such commands creates policy inconsistency and potential for unintended destructive execution.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 211)May include surrounding context.

Uninstall KooCLI

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

sudo rm -rf /usr/local/hcloud/ is a privileged recursive deletion command. Recursive deletions are inherently risky in copied or automated contexts, and the skill context makes it more concerning because delete operations are explicitly out of scope.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

sudo rm -rf /usr/local/hcloud/ is a privileged recursive deletion command. Recursive deletions are inherently risky in copied or automated contexts, and the skill context makes it more concerning because delete operations are explicitly out of scope.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

rm -rf ~/.hcloud/ removes user configuration and likely stored CLI state or credentials. This is destructive, may erase audit-relevant data, and in the context of profile persistence could also wipe configuration unexpectedly.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

rm -rf ~/.hcloud/ removes user configuration and likely stored CLI state or credentials. This is destructive, may erase audit-relevant data, and in the context of profile persistence could also wipe configuration unexpectedly.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.hcloud/cache/ is a targeted cache-removal command, so the impact is narrower than other rm -rf examples. It is still a destructive filesystem operation and should not be normalized in an agent skill without warnings or confirmation guidance.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.hcloud/cache/ is a targeted cache-removal command, so the impact is narrower than other rm -rf examples. It is still a destructive filesystem operation and should not be normalized in an agent skill without warnings or confirmation guidance.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs changing the global CLI language with hcloud configure set --cli-lang=cn, which mutates user environment state without explicit opt-in and may affect unrelated future CLI usage. While not directly compromising confidentiality or integrity of billing data, it can create confusing side effects, alter command/output expectations, and violate least-surprise for a read-only investigation workflow.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
## Verification Path

**Huawei Cloud Gate** — Before matching in `catalog.yml`: if user has not indicated Huawei Cloud / BSS / this skill's billing scope, and cannot be determined from conversation as the Huawei Cloud account for current `hcloud` profile, **first ask one confirmation** "Query current configured Huawei Cloud account and billing period?"; without confirmation, no BSS query execution. Non-Huawei Cloud or other cloud vendor billing → only state out of scope, no evidence gathering.

|Phase|Task|Reference File|Forbidden|
|---|---|---|---|

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The command transmits data to an external host and downloads executable content from it. While normal for software installation, it is still security-relevant because it establishes a network trust dependency and immediately feeds the fetched content into execution flow.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide recommends downloading and executing an external installer script, including a non-interactive mode, without prominent warnings about code execution, trust boundaries, or verification. In an agent or automation context, this pattern can lead to unattended execution of remote code with user or elevated privileges.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The -y non-interactive installation bypasses confirmation prompts and reduces friction for unattended execution of the installer. In agent-driven or scripted environments, this increases the risk of automatic acceptance of privileged or environment-modifying actions without human review.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

Download and run official installation script (interactive)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The instruction uses sudo to place a binary into /usr/local/bin, which is a privileged filesystem modification. On its own this is common admin behavior, but combined with downloaded artifacts it elevates the consequence of a compromised or tampered installer/package.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 49)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

This is another privileged binary placement step using sudo. The risk is not the existence of sudo itself, but encouraging elevation for a downloaded artifact without requiring integrity verification first.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 54)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The macOS installation guidance uses sudo to install the binary into a shared system path. If the downloaded archive is altered or the user misunderstands the command, privileged execution magnifies the impact on the host system.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 73)May include surrounding context.

md
# Intel chips (AMD 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-amd64.tar.gz"
tar -zxvf huaweicloud-cli-mac-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# Apple Silicon (ARM 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

This repeats the same privileged installation pattern for Apple Silicon systems. In an automation or agent setting, normalizing elevation without guardrails can lead to unsafe execution of unverified artifacts.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 78)May include surrounding context.

Apple Silicon (ARM 64-bit)

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-arm64.tar.gz" tar -zxvf huaweicloud-cli-mac-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 3. Windows Systems

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/cli-installation-guide.md:212