Back to skill

Security audit

huawei-cloud-cce-cluster-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Huawei CCE administration, but it grants high-impact cluster control and exposes cluster credentials with some under-scoped confirmation safeguards.

Install only if you intend to let an agent administer Huawei CCE resources. Use temporary, least-privilege IAM credentials, avoid pasting or logging returned kubeconfig, review the remote installer before execution, and patch or manually enforce confirmation for cluster awakening and kubeconfig retrieval before using it against important clusters.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/huawei_cloud/dispatcher.py:31
Finding

Cluster awakening bypasses the documented confirmation gate

Content
View full analysis

Vulnerability Details

File Location: scripts/huawei_cloud/dispatcher.py:31-33
Related Documentation: SKILL.md:25-35
Vulnerability Type: Missing authorization confirmation for a high-risk cloud operation
Risk Level: Medium

Vulnerable Code Snippet:

python
# Cluster (query + lifecycle, excluding create/bind which need special logic)
"huawei_list_cce_clusters":      ("CCE", "ListClusters",                ("region",), False),
"huawei_delete_cce_cluster":     ("CCE", "DeleteCluster",              ("region", "cluster_id"), True),
"huawei_hibernate_cce_cluster":  ("CCE", "HibernateCluster",           ("region", "cluster_id"), True),
"huawei_awake_cce_cluster":      ("CCE", "AwakeCluster",               ("region", "cluster_id"), False),

The Skill documentation states:

markdown
This skill strictly enforces a two-step confirmation mechanism for all dangerous operations.

All dangerous operations require `confirm=true` parameter to execute.

| `huawei_awake_cce_cluster` | Awake | 🟠 High | Resumes cluster from hibernation |

Technical Analysis

The dispatcher represents each simple operation as a tuple whose final Boolean controls confirmation enforcement. For huawei_awake_cce_cluster, that value is False, even though the operation is classified as high risk in the Skill's security constraints.

The generic handler only applies its confirmation gate when that Boolean is true:

python
if confirm_required and params.get("confirm", "").lower() != "true":
    return {
        "success": False,
        "requires_confirmation": True,
        "error": "Confirmation required. Add confirm=true to proceed.",
        "hint": f"Add confirm=true parameter to confirm this operation.",
    }

Consequently, a call without confirm=true proceeds to run(...), which invokes the authenticated Huawei Cloud CCE AwakeCluster operation. The executable path therefore fails to enforce the documented second-step authorization boundar ...[truncated 1187 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the dispatcher registration to enforce confirmation:
python
"huawei_awake_cce_cluster": (
    "CCE",
    "AwakeCluster",
    ("region", "cluster_id"),
    True,
),
  1. Add an automated test that invokes huawei_awake_cce_cluster without confirm=true and verifies:

    • The response contains requires_confirmation: true.
    • No hcloud subprocess or cloud API request occurs.
  2. Add a positive test verifying that the operation executes only when confirm=true is explicitly supplied.

  3. Keep the operation table and SKILL.md generated from, or validated against, a single authoritative risk-policy mapping to prevent future documentation/code drift.

  4. Review other state-changing operations to ensure their executable confirmation flags match the documented security constraints.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (49)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to curl a remote installer script and immediately execute it with bash, a classic supply-chain risk. If the remote host, network path, or object is compromised, arbitrary code executes on the host, and because this skill later uses cloud credentials and may install privileged components, the context materially increases impact.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

  • hcloud (Huawei Cloud KooCLI 7.2+) — drives all Huawei Cloud API calls. Install:

    bash
    curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh
    hcloud version   # verify install
    

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill supports retrieving kubeconfig with a configurable validity period, which is effectively distribution of cluster access credentials/tokens. In a high-privilege cluster-management skill, exposing kubeconfig retrieval without documented authorization checks, minimal duration defaults, or output-handling safeguards increases risk of credential exfiltration and lateral movement.

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
| Parameter | Required | Default | Description |
|-----------|----------|---------|-------------|
| `duration` | ❌ | `30` | Kubeconfig validity period (days), pass as integer |
| `eip_id` | ❌ | auto | EIP ID, auto-find or create if not provided |
| `addon_id` | ❌ | — | Addon ID (UID), required for detail query |

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The core commands explicitly expose a tool for getting cluster kubeconfig, which can grant broad API access to the cluster if mishandled. In this context, the skill already has shell/env capabilities and cloud credentials, so adding direct kubeconfig issuance substantially raises the consequences of misuse or prompt-injection-driven activation.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
|------|----------|------------|
| `huawei_list_cce_clusters` | List all CCE clusters in region | `region` |
| `huawei_get_cce_nodes` | Get detailed node information | `region`, `cluster_id` |
| `huawei_get_cce_kubeconfig` | Get cluster kubeconfig | `region`, `cluster_id`, `duration` |

### Cluster Management

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

This section introduces kubeconfig retrieval functionality in a cluster-management skill, which is inherently credential-access behavior because kubeconfig can provide direct authenticated access to the cluster. In this context the capability is legitimate, but without strong user-facing warnings and output-handling controls it could expose powerful credentials to an unauthorized requester or leak them through logs, chat history, or downstream tooling.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 75)May include surrounding context.

md
> **⚠️ Cost Warning:**
> - **Bind EIP** (5.1, 5.2): EIP incurs bandwidth charges. If auto-creating (5.2), inform the user that a new EIP with traffic billing (5 Mbps) will be created.

## 6. Kubeconfig Retrieval

| # | Acceptance Item | Verification Method | Expected Result |
|---|-----------------|---------------------|-----------------|

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The specific acceptance criterion 'Get kubeconfig' requires the skill to return valid kubeconfig JSON, which may include bearer tokens, certificates, or endpoint data sufficient to administer the cluster. Because this skill manages production-like CCE resources, exposing kubeconfig is more dangerous than in a read-only informational tool: it can enable cluster takeover, workload tampering, secret access, and persistence if obtained by the wrong party.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 79)May include surrounding context.

md
| # | Acceptance Item | Verification Method | Expected Result |
|---|-----------------|---------------------|-----------------|
| 6.1 | Get kubeconfig | `huawei_get_cce_kubeconfig` with `duration=30` | Returns valid kubeconfig JSON |
| 6.2 | Duration as integer | Pass `duration=30` (not `"30d"`) | API returns normally |

## 7. Security & Confirmation Mechanism

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The installation command downloads a remote shell script and immediately executes it with bash, creating a classic supply-chain risk. If the hosting location, transport trust, or script contents are compromised, arbitrary code will run on the host with the user's privileges.

Content

Scanner excerpt · references/cce-api-guide.md (reported line 13)May include surrounding context.

bash
# hcloud (KooCLI 7.2+) — Huawei Cloud API calls
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# kubectl cce — Kubernetes node operations (cordon/uncordon/drain/status)
#   install per https://kubernetes.io/docs/tasks/tools/

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

This documents a tool that retrieves cert-based kubeconfig data via CreateKubernetesClusterCert, which is highly sensitive because kubeconfig can grant direct cluster access and may include client cert material. In a cluster-management skill this capability is expected, but without strict output handling, authorization checks, and redaction controls, it can expose privileged access to the Kubernetes control plane.

Content

Scanner excerpt · references/cce-api-guide.md (reported line 48)May include surrounding context.

md
| `huawei_awake_cce_cluster` | CCE | `AwakeCluster` | |
| `huawei_bind_cce_cluster_eip` | CCE | `UpdateClusterEip` + `ShowCluster` | 2-call: bind then read external endpoint |
| `huawei_unbind_cce_cluster_eip` | CCE | `UpdateClusterEip` | action=unbind |
| `huawei_get_cce_kubeconfig` | CCE | `CreateKubernetesClusterCert` | Returns cert-based kubeconfig data |
| `huawei_list_cce_nodes` / `huawei_get_cce_nodes` | CCE | `ListNodes` | |
| `huawei_create_cce_node` | CCE | `CreateNode` via `--cli-jsonInput` | Uses `resolve_node_login` |
| `huawei_delete_cce_node` | CCE | `DeleteNode` | confirm required |

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

This line explicitly notes that a wrapper returns raw kubeconfig/cert payloads for callers. Even though the node operations do not need kubeconfig, exposing a function whose purpose is to return cluster access material increases the chance of accidental disclosure, misuse by downstream consumers, or unauthorized privilege transfer.

Content

Scanner excerpt · references/cce-api-guide.md (reported line 168)May include surrounding context.

md
- **Environment variables** (`HW_ACCESS_KEY`, `HW_SECRET_KEY`, `HW_SECURITY_TOKEN`) are set inline in the same shell process — no persistent credential files.
- **`--project-id`** is required for the plugin to resolve the CCE management endpoint.
- **No kubeconfig needed**: the plugin handles authentication internally via the CCE API Gateway.
- `huawei_get_cce_kubeconfig` still wraps `CreateKubernetesClusterCert` for callers who want the raw cert payload (not used by node operations).

## hcloud Error Categories

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 302)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cce-api-guide.md (reported line 149)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cce-api-guide.md (reported line 167)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/task-node-management.md (reported line 5)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 18)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 80)May include surrounding context.

md
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/dispatcher.py (reported line 56)May include surrounding context.

python
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/dispatcher.py (reported line 60)May include surrounding context.

python
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/hcloud_runner.py (reported line 254)May include surrounding context.

python
## Overview

Cluster node lifecycle management, including creation, querying, cordon, uncordon, drain, and deletion operations. Node scheduling operations (`cordon`, `uncordon`, `drain`, `status`) run via **kubectl cce** plugin (no cluster EIP or manual kubeconfig needed).

## Create Node Parameters

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command explicitly fetches an external script and immediately executes it (curl ... && bash), creating a direct remote code execution path. In the context of a cluster-management skill, this is especially dangerous because the host likely holds cloud credentials, kubeconfig material, or access to privileged infrastructure, so compromise could lead to cluster takeover or credential theft.

Content

Scanner excerpt · references/troubleshooting.md (reported line 219)May include surrounding context.

hcloud version

Install / upgrade

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

text

### 13. Node drain timeout (`drain ... timeout`)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

Cloning the full parent environment with dict(os.environ) and passing it to a child process causes all existing environment variables to be inherited by kubectl cce, not just the required Huawei credentials. In multi-tenant or plugin-rich agent environments, this can unintentionally disclose unrelated secrets, tokens, proxy credentials, or internal configuration to the child process and anything it executes.

Content

Scanner excerpt · scripts/huawei_cloud/hcloud_runner.py (reported line 270)May include surrounding context.

python
# Pass credentials via environment — only set if not already present
    # (if HW_ACCESS_KEY is already in os.environ, subprocess inherits it naturally)
    env = dict(os.environ)
    if not env.get("HW_ACCESS_KEY"):
        env["HW_ACCESS_KEY"] = ctx.ak
    if not env.get("HW_SECRET_KEY"):

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This function is explicitly designed to obtain kubeconfig material, which is equivalent to credential access for the target cluster. If an unauthorized user can invoke it or if the result is logged, persisted, or shown to the wrong party, it can enable direct cluster compromise, data access, workload manipulation, and lateral movement.

Content

Scanner excerpt · scripts/huawei_cloud/special_ops.py (reported line 245)May include surrounding context.

python
return result


def get_cce_kubeconfig(params: Dict[str, str]) -> Dict[str, Any]:
    """Get cluster kubeconfig via CreateKubernetesClusterCert.

    The API requires duration (integer days, 1-1827) or expire_at.

Static analysis

No suspicious patterns detected.