Back to skill

Security audit

huawei-cloud-cci-instance-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Huawei Cloud CCI administration, but it can perform high-impact cloud changes and has safety controls that are documented more strongly than they are enforced.

Review this skill carefully before installing. Use it only with narrowly scoped Huawei Cloud credentials and a non-production project first. Treat delete, collection-delete, pod exec, Secrets, and RBAC operations as high risk, and do not rely solely on the written two-step confirmation promise because one helper path does not enforce it technically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cci_network_helper.py:170
Finding

Destructive Network Deletion Lacks an Enforced Confirmation Gate

Content
View full analysis

Vulnerability Details

File Location: scripts/cci_network_helper.py, lines 170-183 and 254-280
Vulnerability Type: Missing authorization confirmation for a destructive operation
Risk Level: Medium

Vulnerable code:

python
def delete_network(namespace, name, region, project_id=None):
    ak, sk, security_token = get_credentials()
    if not project_id:
        project_id = get_project_id(region)

    host = f"cci.{region}.myhuaweicloud.com"
    resource_path = (
        f"/apis/networking.cci.io/v1beta1/namespaces/{namespace}/networks/{name}"
    )
    url = f"https://{host}{resource_path}"

    headers = sign_request(
        "DELETE", host, resource_path, "",
        ak, sk, security_token, project_id
    )

    resp = requests.delete(url, headers=headers)
python
delete_parser = subparsers.add_parser(
    "delete", help="Delete a CCI Network"
)
delete_parser.add_argument("--namespace", required=True)
delete_parser.add_argument("--name", required=True)
delete_parser.add_argument("--region", required=True)
delete_parser.add_argument("--project-id", default=None)

# ...

elif args.action == "delete":
    delete_network(
        args.namespace, args.name, args.region, args.project_id
    )

Technical Analysis

The Skill documentation requires two-step confirmation for destructive operations. In particular, SKILL.md lines 24 and 94-113 require the command and resource details to be previewed before execution, followed by explicit user confirmation.

The helper script does not technically enforce that boundary. Its delete subcommand accepts the namespace, network name, region, and optional project ID, then immediately signs and sends an authenticated HTTP DELETE request. It has no interactive prompt, confirmation token, explicit confirmation flag, or dry-run default.

Consequently, a caller can bypass the documented preview-and-confirm workflow by ...[truncated 1303 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the helper's delete action if network deletion is not required through this script.
  • Otherwise, default deletion to a non-destructive preview that displays the exact project, region, namespace, network, API endpoint, and operational consequences.
  • Require an explicit confirmation mechanism before sending the request, such as an interactive prompt that repeats the exact resource identity.
  • For non-interactive use, require a deliberate flag or confirmation token bound to the previewed resource rather than a generic --yes.
  • Reject deletion when confirmation is absent or does not match the selected namespace and network.
  • Consider requiring a dry-run or preflight lookup before confirmation so the user can verify the target resource.
  • Preserve the documented two-step confirmation requirement in every executable entry point rather than relying solely on Agent instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (27)

Tainted flow: 'headers' from os.environ.get (line 208, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cci_network_helper.py (reported line 154)May include surrounding context.

python
headers = sign_request("POST", host, resource_path, body, ak, sk, security_token, project_id)

    resp = requests.post(url, data=body.encode("utf-8"), headers=headers)
    result = json.loads(resp.text)

    if resp.status_code == 201:

Tainted flow: 'headers' from os.environ.get (line 208, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cci_network_helper.py (reported line 210)May include surrounding context.

python
headers = sign_request("GET", host, resource_path, "", ak, sk, security_token, project_id)

    resp = requests.get(url, headers=headers)
    result = json.loads(resp.text)

    if resp.status_code == 200:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior says destructive operations require two-step confirmation and that the skill is an hcloud CLI wrapper, but the referenced implementation reportedly performs direct signed OpenAPI calls and immediate deletion without confirmation. This mismatch is dangerous because users and orchestrators may trust the safer description while the actual behavior bypasses expected safety controls and executes more powerful operations than disclosed.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
| Create/query/delete Namespace | [references/task-namespace-management.md](references/task-namespace-management.md) |
| Create/query/delete Network | [references/task-network-management.md](references/task-network-management.md) |
| Create/query/update/delete/scale Deployment | [references/task-deployment-management.md](references/task-deployment-management.md) |
| Create/query/update/delete StatefulSet | [references/task-statefulset-management.md](references/task-statefulset-management.md) |
| Create/query/delete Pod | [references/task-pod-management.md](references/task-pod-management.md) |
| Create/query/delete EIPPool | [references/task-eippool-management.md](references/task-eippool-management.md) |
| Query status, view logs, events | [references/task-logs-and-status.md](references/task-logs-and-status.md) |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/cci-operation-catalog.md (reported line 52)May include surrounding context.

md
| `readAppsV1NamespacedStatefulSet` | Read StatefulSet |
| `readAppsV1NamespacedStatefulSetStatus` | Read StatefulSet status |
| `patchAppsV1NamespacedStatefulSet` | Update StatefulSet |
| `replaceAppsV1NamespacedStatefulSet` | Replace StatefulSet |
| `deleteAppsV1NamespacedStatefulSet` | Delete StatefulSet |
| `deleteAppsV1CollectionNamespacedStatefulSet` | Delete all StatefulSets in namespace |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Pod exec provides interactive command execution inside running containers, which is far more powerful than ordinary lifecycle management. If invoked by an agent or user with broad credentials, it can be used to inspect secrets, alter workloads, pivot within the environment, or run arbitrary commands in application containers.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
| `cci:statefulset:get` | Read StatefulSet |
| `cci:statefulset:list` | List StatefulSets |
| `cci:statefulset:update` | Update StatefulSet |
| `cci:statefulset:delete` | Delete StatefulSet |
| `vpc:vpcs:list` | List VPCs (for Network creation) |
| `vpc:subnets:get` | Read subnet details (for Network creation) |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/cci-operation-catalog.md (reported line 53)May include surrounding context.

md
| `cci:statefulset:get` | Read StatefulSet |
| `cci:statefulset:list` | List StatefulSets |
| `cci:statefulset:update` | Update StatefulSet |
| `cci:statefulset:delete` | Delete StatefulSet |
| `vpc:vpcs:list` | List VPCs (for Network creation) |
| `vpc:subnets:get` | Read subnet details (for Network creation) |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/iam-policies.md (reported line 28)May include surrounding context.

md
| `cci:statefulset:get` | Read StatefulSet |
| `cci:statefulset:list` | List StatefulSets |
| `cci:statefulset:update` | Update StatefulSet |
| `cci:statefulset:delete` | Delete StatefulSet |
| `vpc:vpcs:list` | List VPCs (for Network creation) |
| `vpc:subnets:get` | Read subnet details (for Network creation) |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/task-statefulset-management.md (reported line 86)May include surrounding context.

md
| `cci:statefulset:get` | Read StatefulSet |
| `cci:statefulset:list` | List StatefulSets |
| `cci:statefulset:update` | Update StatefulSet |
| `cci:statefulset:delete` | Delete StatefulSet |
| `vpc:vpcs:list` | List VPCs (for Network creation) |
| `vpc:subnets:get` | Read subnet details (for Network creation) |

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cci_network_helper.py (reported line 10)May include surrounding context.

python
#!/usr/bin/env python3
"""
CCI Network Creation Helper Script

This script creates a CCI Network by directly calling the CCI OpenAPI,
bypassing hcloud CLI's limitation with annotation keys containing dots.

hcloud CLI treats dots in annotation keys as nested object delimiters,
making it impossible to pass 'network.alpha.kubernetes.io/default-security-group'
via CLI parameters or --cli-jsonInput (which also doesn't properly transmit
annotations in actual API requests, despite showing them in --dryrun).

Usage:
    python cci_network_helper.py create \
        --namespace <ns-name> \
        --name <network-name> \
        --vpc-id <vpc-id> \
        --subnet-id <neutron-subnet-id> \
        --network-id <neutron-network-id> \
        --security-group-id <sg-id> \
        --region <region>

    python cci_network_helper.py delete \
        --namespace <ns-name> \
        --name <network-name> \
        --region <region>

    python cci_network_helper.py st

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This is a concrete tool-parameter abuse issue: attacker-controlled input is interpolated into a shell command used to invoke another administrative tool. Because the skill manages cloud infrastructure, successful command injection could lead to host compromise, credential theft, or unauthorized cloud actions beyond the intended operation.

Content

Scanner excerpt · scripts/cci_network_helper.py (reported line 83)May include surrounding context.

python
import subprocess
    try:
        cmd = f"hcloud IAM KeystoneListProjects --cli-region={region} --cli-output=json"
        result = subprocess.run(
            cmd, capture_output=True, timeout=15,
            encoding="utf-8", errors="replace", shell=True,
        )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes and enables shell, environment-variable, and network-capable operations but does not declare any explicit tool scope or permission boundaries. That creates an authorization gap: a host agent may invoke powerful capabilities without a clear least-privilege contract, increasing the chance of unintended command execution or credential-accessing behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains very broad generic terms such as namespace, pod, logs, and status, which can cause the skill to activate in routine conversations unrelated to Huawei CCI administration. Overbroad activation increases the risk that a high-privilege operational skill is selected accidentally, exposing shell/network actions in contexts where they were not intended.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
### Credential Security

- **Never expose AK/SK/SecurityToken values** in conversation, commands, or output
- **Never ask user to input AK/SK/SecurityToken directly** in conversation
- **Only use** `hcloud configure list` to check credential status (presence only, not values)
- **Prefer** profile mode or environment variables over explicit AK/SK parameters

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The reference lists many delete and collection-delete operations without inline warnings about blast radius, prerequisites, or irreversible effects. In an agent context, terse destructive documentation increases the risk that commands are selected or synthesized without sufficient user awareness, especially for namespace-wide and cascading deletions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The catalog materially expands the skill from CCI instance lifecycle management into broader Kubernetes administration, including Secrets, RBAC, API discovery, storage, and cluster-scoped reads. This violates least privilege at the skill-design level and can enable users or downstream agents to perform sensitive actions outside the declared purpose, increasing the chance of privilege misuse and data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cleanup workflow includes bulk deletion commands and explicitly recommends deleting the namespace directly, which cascades deletion of all contained resources. Although the skill metadata mentions two-step confirmation for destructive operations, this document does not require an explicit pre-execution verification step such as confirming the target namespace, listing affected resources, or requiring user acknowledgment of the blast radius, so operator error could cause unintended large-scale deletion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest says the skill provides full lifecycle management using hcloud CLI, implying a single CLI-based implementation model. The documentation contradicts that expectation by stating that network creation is performed by scripts/cci_network_helper.py with independent credentials, which means actual behavior extends beyond the described CLI-only approach.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest frames this skill as operating CCI lifecycle management using the hcloud CLI, but this documentation states that network creation relies on a separate Python helper script with its own HW_ACCESS_KEY/HW_SECRET_KEY/HW_SECURITY_TOKEN environment variables. That adds a second authentication surface and non-CLI execution path that is not clearly justified by the stated CLI-focused purpose.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/task-statefulset-management.md (reported line 92)May include surrounding context.

hcloud CCI deleteAppsV1NamespacedStatefulSet --name= --namespace= --cli-region=

text

**WARNING:** PVCs created by volumeClaimTemplates are NOT automatically deleted when the StatefulSet is deleted. Manual cleanup is required:

```bash
hcloud CCI deleteCoreV1NamespacedPersistentVolumeClaim --name=<pvc-name> --namespace=<ns-name> --cli-region=<region>

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 63)May include surrounding context.

md
Two-step confirmation process:

1. **Test without confirmation:** show preview and warning only, do not execute deletion.
2. **Test with confirmation:** verify the resource is actually deleted by attempting to read it (should return 404 or empty result).

## 8. Complete Verification Checklist

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The script builds a shell command with an untrusted CLI argument (region) and executes it with shell=True. An attacker who can influence --region could inject arbitrary shell metacharacters and execute commands on the host running the skill, which is especially dangerous in an agent context where parameters may come from user prompts.

Content

Scanner excerpt · scripts/cci_network_helper.py (reported line 83)May include surrounding context.

python
import subprocess
    try:
        cmd = f"hcloud IAM KeystoneListProjects --cli-region={region} --cli-output=json"
        result = subprocess.run(
            cmd, capture_output=True, timeout=15,
            encoding="utf-8", errors="replace", shell=True,
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The helper performs destructive deletion immediately when invoked, with no interactive confirmation, dry-run mode, or explicit force flag. In an agent skill that is supposed to enforce two-step confirmation for destructive operations, this increases the risk of accidental or prompt-induced resource deletion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file states a fixed default region in natural language and then uses that same region throughout all example commands. Per the policy, locale or region constraints should either be user-selectable or clearly justified as a region-specific tool; this document does not provide that context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.