Back to skill

Security audit

huawei-cloud-cce-alarm-correlation-engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Huawei Cloud AOM/CCE alarm operations tool with high-impact rule-management actions that are purpose-aligned and gated by preview and confirmation.

Install only for Huawei Cloud environments where the agent is allowed to administer AOM alarm and notification rules. Prefer a least-privilege hcloud profile, use read-only commands first, review every preview carefully, and only approve confirm=true for changes you intend to persist in the cloud account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a fully featured Huawei Cloud AOM/CCE alarm-management skill, but the provided code chunk does not implement any of those behaviors. It is only an empty package initializer with a generic docstring. Because the actual code lacks the stated primary functionality entirely, the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/verification-method.md (reported line 53)May include surrounding context.

md
Expected result:

- Cluster-scoped queries only return rules related to the target `cluster_id`.
- `cluster_name` is not accepted by `huawei_list_aom_alarm_rules`.

## Mutation Verification

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly relies on shell execution (python3 scripts/huawei-cloud.py, local hcloud), environment-based credentials, and file-backed JSON inputs, yet it does not declare an explicit tool scope such as allowed-tools or permissions. That creates an avoidable trust gap: a host agent may grant broader shell, environment, or file access than the skill actually needs, increasing the blast radius if the skill is misused or if user-controlled parameters are passed unsafely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage rules instruct users to prefer the Chinese event description##Event name format and describe automatic mapping from Chinese descriptions, which imposes a Chinese-language convention. Because the file does not offer an alternative locale choice or explain that the skill is intentionally limited to a China-specific environment, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code generates natural-language output such as reports, labels, and status messages entirely in Chinese, including the main report text and returned message fields. That creates a language/locale policy issue because users are forced into a specific language with no opt-in, fallback, or documented regional justification in this file.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/huawei_cloud/common.py (reported line 167)May include surrounding context.

python
command.append("--dryrun")

    try:
        completed = subprocess.run(command, text=True, capture_output=True, timeout=timeout, check=False)
    except subprocess.TimeoutExpired as exc:
        return {
            "success": False,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/huawei_cloud/common.py (reported line 216)May include surrounding context.

python
command.append("--dryrun")

    try:
        completed = subprocess.run(command, text=True, capture_output=True, timeout=timeout, check=False)
    except subprocess.TimeoutExpired as exc:
        return {
            "success": False,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Multiple handlers accept sensitive credential fields such as ak, sk, and project_id and pass them into downstream operations, but this file provides no confirmation prompt, logging, or explanatory comment/docstring warning that credentials will be used. For code files, accessing sensitive environment-style credentials or transmitting them in API operations should have some visible disclosure unless clearly documented elsewhere in the skill description, which is not present in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description frames the skill as alarm correlation/querying, but the declared tools include privileged state-changing operations such as creating, updating, deleting, enabling, and disabling alarm and action rules. This mismatch can mislead operators, reviewers, or policy systems into authorizing a skill with broader control-plane impact than expected, increasing the risk of unintended or unauthorized configuration changes in production monitoring.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.