Back to skill

Security audit

huawei-cloud-cce-metric-analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed read-only Huawei Cloud CCE monitoring skill, but it should be used with least-privilege cloud and Kubernetes credentials because it reads sensitive operational metadata.

Install only in an environment where the Huawei Cloud credentials and Kubernetes RBAC are limited to the documented read-only operations. Be aware that certificate checks read Ingress-referenced TLS Secrets and kubectl access may generate a temporary kubeconfig; verify the external kubectl-cce plugin before installing it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises substantial Huawei Cloud metric-analysis functionality, including many specific metric query and anomaly-detection capabilities. However, the provided code chunk is only an init.py file with a docstring and no executable logic. Since the actual code does not implement the declared capabilities or demonstrate the stated primary purpose, this is a clear description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description focuses on metric analysis across CCE and related Huawei Cloud resources, including CPU/memory/disk/QPS/latency metrics, TopN rankings, and anomaly detection. The supplied code instead contains infrastructure/helper operations: listing CCE clusters and nodes, listing pods, and retrieving ingress TLS certificate information from Kubernetes secrets. While certificate expiration is mentioned in the declared purpose, the overall described primary purpose is metric analysis, and this code chunk is largely not performing that role. The ingress certificate inspection is only a partial overlap; most implemented behavior is cluster/node enumeration and secret/certificate inspection, which are materially different from the declared metric-analysis functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code generally aligns with the high-level theme of CCE metric aggregation and anomaly detection, but the declared description is materially broader than what this chunk actually implements. Concretely, the code fetches pod/node TopN usage metrics, CoreDNS/nginx-ingress/autoscaler component summaries, and associated ELB/NAT/EIP metrics. However, it does not query ECS metrics, and it does not implement control-plane metrics such as apiserver, etcd, controller manager, or scheduler, all of which are explicitly advertised. It also does not directly implement many declared metric categories like certificate expiration, QPS, latency, request, connection, scaling, or error-rate across the listed resources; only whatever is returned by downstream component metric helpers may appear in summarized form. Additionally, the implementation includes resource scoping via cluster network lookup and kubectl-based LoadBalancer service enumeration/correlation, which is related but not mentioned in the declared purpose. Overall, this is a description-behavior mismatch due to significant overstatement of supported capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code substantially matches the core declared theme of Huawei Cloud CCE/AOM metric analysis and does implement many listed capabilities: Pod/Node metrics, CoreDNS, nginx-ingress, autoscaler/HPA, control-plane metrics, TopN rankings, and certificate checks. However, there are material description-behavior mismatches. First, the code includes additional undeclared capabilities for GPU/xGPU monitoring at both node and pod level, which are not mentioned in the description. Second, the description claims support for ECS/ELB/EIP/NAT cloud resource metrics, but this code chunk does not implement those cloud resource metric queries at all. Third, the description mentions aggregation with anomaly detection; the implementation only provides relatively simple threshold-based status classification and summaries, not broader anomaly-detection logic. Therefore the declared description does not accurately represent this specific code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a CCE metric analysis skill centered on cluster/component metrics and monitoring workflows, with some mention of querying cloud resource metrics such as ELB. However, this code chunk is specifically an ELB utility module. Two of its three functions perform ELB inventory/configuration discovery (load balancers and listeners), which is not represented in the declared purpose. The third function does retrieve ELB metrics, which partially aligns with the declared cloud resource metric-query capability, but the module’s overall behavior is more specific and broader in a different direction: ELB enumeration plus ELB metric retrieval, not CCE metric analysis, TopN aggregation, or anomaly detection. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on metric analysis and monitoring use cases: querying performance/resource metrics, TopN rankings, cloud metrics, aggregation, and anomaly detection. The supplied code does not implement metric collection, metric analysis, TopN ranking, anomaly detection, or AOM/cloud metric queries. Instead, it establishes access to a CCE Kubernetes cluster using Huawei Cloud CCE APIs, creates kubeconfig credentials/certificates, and runs kubectl commands to fetch Kubernetes objects (pods, services, ingresses, secrets). This is a materially different primary purpose and includes sensitive undeclared capability (secret retrieval). While it does interact with CCE clusters on Huawei Cloud, the behavior is operational cluster resource access, not metrics analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on CCE metric analysis and cluster observability use cases, with broad emphasis on Kubernetes component metrics and analysis features. This code chunk instead targets network-related Huawei Cloud resources: EIP and NAT. While the description does mention EIP/NAT cloud resource metrics, the code goes beyond that by also listing EIPs and NAT gateways, and it lacks the core advertised CCE/AOM analysis behaviors such as cluster/component metrics, TopN ranking, aggregation, and anomaly detection. Therefore this chunk does not accurately represent the declared primary purpose and includes undeclared resource-listing capabilities.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill explicitly involves kubeconfig files, environment-based AK/SK handling, security tokens, and signed requests, all of which are sensitive credential material or credential-adjacent artifacts. Even though the text says not to print or persist them, the documented workflow normalizes access to these secrets in a broad shell/network-enabled skill, increasing the risk of accidental disclosure, over-collection, or misuse if the dispatcher or surrounding agent is compromised.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

python3 scripts/huawei-cloud.py key=value key=value

text

The dispatcher converts cloud service queries to KooCLI calls. AOM Prometheus range queries use signed HTTPS requests because that path is not compatible with hcloud. Avoid Kubernetes resource reads unless the tool explicitly needs Pod labels, Ingress TLS Secrets, or LoadBalancer Services. Quote values containing spaces, `>`, `<`, `|`, JSON, or PromQL; never print or persist AK/SK, security tokens, kubeconfig files, or temporary payloads; keep Kubernetes/AOM PromQL scoped with `cluster="<cluster_id>"`.

### 1. CCE Pod Metrics

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Generating or using kubeconfig through a cluster EIP and falling back to a kubectl plugin materially increases credential exposure and cluster-access risk, especially in an agent context with shell and network capability. This is more dangerous than ordinary metrics collection because it expands from cloud metrics into direct cluster authentication workflows, potentially exposing admin-equivalent access artifacts or enabling broad Kubernetes API reads beyond what users may expect from a monitoring skill.

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

md
It also includes CoreDNS, nginx-ingress, and autoscaler summaries. Cloud resources are scoped to the current cluster when an association can be proven: ELB is matched through LoadBalancer Service IP/EIP, NAT Gateway is filtered by the cluster VPC, and EIP is limited to associated ELB/NAT/Service IPs.

LoadBalancer Service discovery uses `kubectl` with generated kubeconfig through the cluster EIP when external access is available. If the cluster has no EIP, it uses the `kubectl cce` plugin. If neither path works, aggregation fails.

## Risk Levels

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 21)May include surrounding context.

md
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.

md
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/iam-policies.md (reported line 41)May include surrounding context.

md
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 63)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 75)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 76)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 77)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 78)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 79)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 82)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 84)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 91)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 94)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 98)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 105)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/huawei_cloud/kubectl_client.py (reported line 106)May include surrounding context.

python
| `python3` | Run the dispatcher and parse results | All tools |
| `hcloud` / KooCLI | Query Huawei Cloud CCE, ECS, ELB, EIP, NAT, CES, IAM, and add-on metadata | Cloud service and CES metric tools |
| `kubectl` | Read Kubernetes resources only when AOM/hcloud cannot derive them | Pod label filtering, Ingress TLS checks, LoadBalancer Service association |
| `kubectl-cce` | Connect to CCE clusters without direct kubeconfig access | Same Kubernetes resource-read paths |

## hcloud Setup

Static analysis

No suspicious patterns detected.