Back to skill

Security audit

huawei-cloud-business-tf-support

Security checks for vulnerabilities and agentic risk

Overview

This skill should go to Review because its billing-only description does not match its broader cloud resource querying scripts, and its setup/API traffic disables certificate checks while using cloud credentials.

Install only if you intend to grant this skill read access to Huawei Cloud billing and broader resource metadata, not just billing. Use least-privilege read-only credentials, treat query output as sensitive, and avoid running it on untrusted networks until TLS verification and the get-pip.py bootstrap path are fixed or removed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/ensure_env.py:278
Finding

Remote Python bootstrap downloaded over unverified TLS and executed

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py, lines 28 and 278–294
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: High

Vulnerable Code

python
ssl._create_default_https_context = ssl._create_unverified_context
python
get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py")
urls = [
    "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py",
    "https://bootstrap.pypa.io/get-pip.py",
]

ctx = ssl._create_unverified_context()

for url in urls:
    info(f"尝试下载 get-pip.py: {url}")
    try:
        urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    except Exception as e:
        print(f"    下载失败: {e}")
        continue

    rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)

Technical Analysis

The mandatory environment setup attempts to install pip when neither an existing pip installation nor ensurepip is available. As a fallback, it downloads get-pip.py from an external URL and immediately executes the downloaded file with the active Python interpreter.

Both the process-wide HTTPS context and the explicit download context disable certificate verification. Consequently, HTTPS does not authenticate the remote server. No signature or pinned cryptographic digest is checked before execution.

The downloaded response is therefore attacker-influenced when a network-positioned adversary, compromised proxy, or other party capable of intercepting the connection is present. This crosses the trust boundary from untrusted network content to local executable code.

The Skill documentation requires users to run the environment check before executing queries. The vulnerable fallback is reached when:

  1. The environment check is invoked.
  2. python -m pip --version fails.
  3. python -m ensurepip --upgrade also fails.
  4. One of the configured download URLs is reachable through an attacker-controlled network path.

Attack Path

...[truncated 1458 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the global TLS-verification override:
    python
    ssl._create_default_https_context = ssl._create_unverified_context
    
  2. Do not create or pass an unverified SSL context to urlretrieve.
  3. Use Python's default certificate-verifying TLS context:
    python
    ctx = ssl.create_default_context()
    urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    
  4. Verify the downloaded bootstrap using a pinned cryptographic digest or trusted signature before execution.
  5. Prefer a single canonical HTTPS source rather than automatically executing content from multiple fallback sources.
  6. If secure bootstrap verification cannot be completed, fail safely and provide manual installation instructions instead of executing the file.
  7. Create the temporary file securely, restrict its permissions, and remove it after use.
  8. Consider eliminating remote bootstrap execution entirely and requiring pip or ensurepip to be provisioned through the operating system's trusted package mechanism.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config.py:51
Finding

TLS certificate verification disabled for authenticated Huawei Cloud API requests

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py, lines 8–9 and 51–54
Vulnerability Type: Improper certificate validation
Risk Level: High

Vulnerable Code

python
# 抑制因 ignore_ssl_verification 产生的 InsecureRequestWarning
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
python
http_config = HttpConfig.get_default_config()
http_config.ignore_ssl_verification = True
http_config.timeout = (30, 60)
http_config.retry_times = 3

Technical Analysis

build_http_config() explicitly configures the Huawei Cloud SDK to ignore TLS certificate validation. It also suppresses the warning that would ordinarily notify the user about insecure HTTPS connections.

This shared configuration is used by the credential validation and cloud query paths. These requests are authenticated using the user's Huawei Cloud access key, secret key, and optional security token. Disabling certificate validation means the client does not establish that it is communicating with the intended Huawei Cloud endpoint.

A network-positioned attacker can therefore impersonate an API endpoint, receive authenticated requests, and return fabricated API responses. While the secret key itself is used for request signing rather than necessarily being transmitted directly, authenticated request material and temporary security-token data may be exposed to the impersonating peer. Responses consumed by the Skill also lose authenticity and integrity guarantees.

Proxy support increases the relevance of the trust boundary because HTTPS_PROXY or HTTP_PROXY may direct these requests through an intermediary. Proxy support is legitimate functionality, but it must not disable endpoint certificate validation.

Attack Path

  1. The user runs the mandatory environment check or any supported cloud query script.
  2. The script loads Huawei Cloud credentials from the environment.
  3. The script calls build_http_config(), which sets:
    python
    http_conf
    

...[truncated 1602 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the insecure SDK setting:
    python
    http_config.ignore_ssl_verification = True
    
  2. Retain the Huawei Cloud SDK's default certificate verification behavior.
  3. Remove suppression of InsecureRequestWarning so accidental insecure configurations remain visible.
  4. If an enterprise TLS-inspection proxy requires a private certificate authority, support an explicitly configured CA bundle rather than disabling verification globally.
  5. Validate proxy configuration and document that proxy credentials and endpoints must come from a trusted administrator-controlled source.
  6. Add automated tests that reject invalid, expired, hostname-mismatched, and self-signed certificates unless the signing CA is explicitly trusted.
  7. Avoid providing a general-purpose “disable verification” option. If one is necessary for isolated development, require an explicit opt-in, display a prominent warning, and prevent its use in credential validation or authenticated production queries.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (108)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

SFS Turbo share-type metadata is unrelated to the declared billing-only mission and exposes storage capability details. The risk comes from concealed scope expansion, not from write actions, because read-only cloud reconnaissance can still be sensitive.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest says the skill is only for Huawei Cloud billing/pricing inquiries, but the body of SKILL.md describes a general cloud resource query tool. This direct inconsistency is dangerous because agents, users, and governance systems may approve the skill for sensitive credentials based on a much narrower stated purpose than its documented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The capability scope explicitly expands from billing inquiries to generic resource enumeration and dependency discovery. That hidden broadening increases the chance of unauthorized reconnaissance and breaks least-privilege expectations for a billing-only skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script enumerates bare-metal server flavor details and exposes infrastructure resource metadata that falls outside the skill's declared billing/pricing-only scope. Even though it is read-only, this expands the agent's effective capability into infrastructure discovery, which can aid unauthorized reconnaissance and violate least-privilege expectations for a finance-focused skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code builds a live BMS client and performs full flavor discovery, then adds local sorting, filtering, and pagination features that make reconnaissance more usable. In the context of a Terraform billing/pricing support skill, that unjustified discovery capability increases the risk of misuse for environment mapping and resource planning outside the approved business purpose.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云资源查询 - 环境检查前置脚本 (Windows PowerShell)
#>

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script enumerates ECS flavors through the compute service, which is outside the skill’s declared billing/pricing-only scope. Even though it is read-only, this expands the skill’s effective permissions and functionality into infrastructure discovery, enabling cloud environment reconnaissance that a caller would not expect from a billing support skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script performs ELB flavor enumeration through the ELB service API, which goes beyond the skill’s declared billing/pricing-only scope. Even though it is read-only, it enables infrastructure and capacity discovery that can expose deployment characteristics and be repurposed for broader reconnaissance, making the mismatch especially risky in an agent skill that should only answer billing-related queries.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 69)May include surrounding context.

python
# 用 venv Python 重新执行当前脚本
    print(f"  使用虚拟环境 Python: {venv_python}")
    os.execv(venv_python, [venv_python] + sys.argv)

def info(msg):
    print(f"  {msg}")

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
print()
    info("请安装 Python 3.6+ 后重试,参考:")
    print("    Windows : winget install Python.Python.3.11")
    print("    Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip python3-venv")
    print("    CentOS  : sudo yum install -y python3 python3-pip")
    print("    Fedora  : sudo dnf install -y python3 python3-pip")
    print("    macOS   : brew install python@3.11")

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ensure_env.py:284