Analyze CDN domain traffic anomalies using hcloud CLI. Query billing mode and traffic/bandwidth metrics for specified domains, compare against 3-month baseline and absolute thresholds to identify traffic theft or abuse. Use this skill when the user wants to: (1) analyze CDN domain traffic anomalies, (2) check if a domain has traffic theft or abuse, (3) query CDN billing mode and traffic/bandwidth metrics, (4) compare current traffic against historical baseline. Triggers include: "CDN流量异常", "流量异常分析", "域名流量分析", "流量盗刷", "带宽异常", "95带宽异常", "流量突增", "流量对比", "基准分析", "traffic anomaly", "bandwidth anomaly", "CDN traffic analysis", "traffic theft detection", "baseline comparison"
This skill analyzes CDN domain traffic anomalies by querying billing mode and corresponding traffic/bandwidth metrics. It automatically determines the appropriate metric based on the
account's billing mode (bw_95, flux, combine_flux, bw, bw_peak), queries historical data over a configurable time range, establishes a 3-month baseline for comparison, and identifies
potential traffic theft or abuse using both absolute thresholds and relative baseline deviation.
Key Features:
Automatic billing mode detection and metric selection
Support for all billing modes: bw_95, flux, combine_flux, bw, bw_peak
Comprehensive analysis reports with baseline comparison and daily breakdowns
Tool: hcloud CLI (KooCLI) Timestamp Tool: scripts/cdn_timestamp.py (built-in) Analysis Scope: Past 7 days for current window (configurable); past 3 months for baseline Core Principle: Query only the metric corresponding to the billing mode; use API capabilities efficiently to cover both current and baseline windows with minimal API calls
Triggers
Use this skill when the user request matches one of the following patterns (user-level example inputs):
User Input Example
Trigger Intent
"Is example.com's traffic being stolen or abused?"
Traffic theft detection
"Analyze whether CDN bandwidth has surged abnormally in the last 7 days"
Bandwidth anomaly analysis
"Compare traffic over the past 3 months with the current period for anomalies"
3-month baseline comparison
"Check our account's CDN billing mode and domain list"
Billing mode / domain query
"Why is example.com's 95th percentile bandwidth so high?"
Also triggered by the trigger phrases listed in the frontmatter description (e.g., CDN流量异常, 流量盗刷, 带宽异常, traffic anomaly).
Near-miss / Do NOT use
Do NOT use this skill for:
❌ Any CDN write operation: create/delete domains, modify domain config, refresh/preheat, enable/disable domains, change billing mode, etc. — this skill is strictly read-only and must
refuse such requests (see all 55 prohibited operations in references/prohibited-operations.md)
❌ Traffic analysis requiring hourly or finer granularity — this skill works at daily granularity (interval=86400)
❌ Traffic/bandwidth analysis for non-CDN services (e.g., ECS, ELB, OBS traffic) — this skill only covers CDN domains
❌ Operational tasks such as domain config changes, certificate management, or anti-hotlink configuration
❌ Scenarios without hcloud credentials or CDN permissions (complete the credential check in the Authentication section first)
❌ Cross-border / overseas region analysis — the CDN CLI only accepts cn-north-1 and ap-southeast-1; other regions return [USE_ERROR]
⛔ Prohibited Operations (Security Constraints)
This skill strictly forbids all non-GET (write/modify/delete) CDN operations, regardless of user requests.
Total: 55 prohibited operations (24 POST + 25 PUT + 6 DELETE).
If a user requests a prohibited operation, you must refuse and inform:
"Per security constraints, this skill does not allow write/delete/modify operations. This skill is read-only for traffic analysis. Please use the Huawei Cloud CDN console or run the hcloud
CLI manually for configuration changes. The complete list of 55 prohibited operations is documented in references/prohibited-operations.md."
Prerequisite check: Huawei Cloud CLI (hcloud / KooCLI) >= 3.2.0 required
Run hcloud version to verify version >= 3.2.0. If not installed or version is too low,
see references/cli-installation-guide.md for installation guide.
bash
hcloud version
Prerequisite check: Python >= 3.8 required (for timestamp calculation)
Run python --version to verify version >= 3.8.
bash
python --version
Prerequisite check: hcloud credentials configured
Before performing CDN operations, you must verify hcloud credentials are configured:
bash
hcloud configure list
If no valid credentials exist, stop and guide the user to configure credentials.
⚠️ hcloud parameter format requirements
hcloud (KooCLI) all parameters must use the --param=value format (connected with equals sign); space-separated format is not supported.
CDN is a global service (is_global=true). The hcloud CLI for CDN only accepts cn-north-1 and ap-southeast-1 (both map to the same endpoint cdn.myhuaweicloud.com); cn-north-4 is
rejected with [USE_ERROR].
Recommended: Always use cn-north-1.
Prohibited from reading, echoing, or printing AK/SK values
Prohibited from asking the user to input AK/SK directly in the conversation
Prohibited from using hcloud configure set to pass plaintext credential values
Prohibited from accepting AK/SK directly provided by the user in the conversation
Only allowed to read credentials from environment variables or configured CLI config files
⚠️ Important: Handling user-provided credentials
If a user attempts to provide AK/SK directly (e.g., "my AK is xxx, SK is yyy"):
Stop immediately - Do not execute any commands
Politely refuse and return the following message:
text
For account security, please do not provide Huawei Cloud Access Key ID and Access Key Secret directly in the conversation.
Please use one of the following secure methods to configure credentials:
Method 1: Interactive configuration (recommended)
hcloud configure
# Enter AK/SK as prompted; credentials will be securely stored in a local config file
Method 2: Environment variable configuration
export HUAWEICLOUD_SDK_AK=<your-access-key-id>
export HUAWEICLOUD_SDK_SK=<your-secret-key>
After configuration is complete, please retry your request.
Do not continue executing any Huawei Cloud operations until credentials are configured
Check CLI configuration:
bash
hcloud configure list
Check whether the output contains valid configuration (AK/SK, IAM, etc.).
Query daily traffic statistics (1 current 7-day + 3×30-day baseline queries for flux/bw paths)
--stat_type, --interval, --service_area
Notes:
All commands require --cli-region=cn-north-1
Timestamps must be in milliseconds (e.g., 1785081600000)
Use scripts/cdn_timestamp.py to calculate timestamps
Use scripts/cdn_timestamp.py --baseline for 3×30-day baseline windows
ShowBandwidthCalc: max 31-day range, single aggregate value (no per-day breakdown), rate limit 2 calls/s
ShowDomainStats/v2: interval=86400 (1 day) max query range is 31-32 days — a 97-day single query fails with CDN.0202; one data point per day; rate limit 15 calls/s; baseline must be
split into 3×30-day queries
Parameter Confirmation
Before executing the analysis, confirm the following parameters with the user:
Parameter
Required
Description
Default
Example
domain_name
Yes
Target CDN domain to analyze
None
example.com
--days
No
Number of days for current window analysis
7
14
--cli-region
Yes
Huawei Cloud region
cn-north-1
cn-north-1
User Confirmation Checklist:
Target domain name provided or selected from domain list
Analysis time range confirmed (default: past 7 days for current window)
User understands this is a read-only analysis operation
User understands the baseline comparison spans past 3 months
Core Workflows
Target domain is required before any analysis step.
If the user did not provide a target domain, ask the user for the domain name and wait for the reply before starting.
Only if the user does not know the domain or asks you to look it up, list the account's domains via hcloud CDN ListDomains/v2 (Step 2) and ask the user to choose one.
Never start the analysis without an explicit user-provided domain: do not guess a domain, do not fall back to an example/default domain, and do not pick a domain from the list yourself.
Step 1: Query Account Billing Mode
Query billing mode via hcloud CLI to determine which metric to analyze.
Query the corresponding metric for the baseline window (past 3 months) based on billing mode.
bw_95: 3 separate calls to ShowBandwidthCalc, each covering one non-overlapping 30-day window (API max range is 31 days). Sleep 0.6s between calls to respect the 2 calls/s rate limit.
flux / bw: 4 separate ShowDomainStats/v2 calls — 1 for the current 7-day window (from Step 5) plus 3 for the 3×30-day baseline windows (interval=86400, aligned to UTC+8 midnight).
The API max range for interval=86400 is 31-32 days, so a single 97-day query fails (CDN.0202). Compute baseline statistics (mean / P95 / max) from the 3 aggregated 30-day windows,
consistent with the bw_95 path.
⚠️ Anomalous — Absolute threshold exceeded; strong signal of traffic theft
👀 Watch — Does not exceed absolute threshold, but exceeds baseline × 1.5; potential relative surge worth investigating
✅ Normal — Falls within both absolute and relative thresholds
No-data domains (result: {} or value: 0) are always treated as Normal.
Output Format
Every analysis produces a unified CDN traffic anomaly analysis report. The full templates for all three tiers (⚠️ Anomalous / 👀 Watch / ✅ Normal) are in
references/task-threshold-judgment.md — follow those templates exactly.
Verify --key=value format and --cli-region=cn-north-1
Recovery policy per failure mode: retry (rate limit / transient errors, up to 2 attempts with backoff) → degrade (split query range, use available data) → report failure (stop and
explain to the user). Never fabricate data or continue with invalid results.
Self-check before output: verify (1) billing mode matches the queried metric, (2) the 3 baseline windows are non-overlapping with the current window, (3) threshold comparison uses the
correct units (bit/s vs Byte) and direction (≥ vs >).
FAQ
Question
Answer
Why does ShowBandwidthCalc return only a single value?
This is expected behavior: the API returns a single P95 aggregate value for the query period with no per-day breakdown, and its maximum query range is 31 days. Use ShowDomainStats/v2 for per-day data.
Why can't I query 97 days in one call?
ShowDomainStats/v2 with interval=86400 has a maximum query range of 31-32 days; a single 97-day query fails with CDN.0202. The baseline must be split into 3 non-overlapping 30-day windows.
Is a domain with no traffic data (result: {} / value: 0) considered anomalous?
No. Domains with no data are always treated as Normal (see Threshold Rules Summary); you may note in the report that the domain had no traffic during the query period.
Why is --cli-region=cn-north-1 always recommended?
CDN is a global service; the CLI only accepts cn-north-1 and ap-southeast-1 (both map to the same endpoint), and cn-north-4 is rejected ([USE_ERROR]).
What if I hit a rate limit error?
ShowBandwidthCalc is limited to 2 calls/s: add sleep 0.6 between commands; ShowDomainStats is limited to 15 calls/s and usually needs no handling.
The domain is not in the account's online domain list?
Stop the analysis and ask the user to verify the domain spelling/status/account (see the Domain Not Found section in troubleshooting.md).
The user requests a write operation (e.g., cache refresh, config change)?
Refuse and explain that this skill is read-only (see prohibited-operations.md); direct the user to the CDN console or manual hcloud CLI execution.
Owner: cdn-ops Maintenance: For major changes, update this table and bump the version number (SemVer). Deprecation/retirement requires review by the cdn-ops team and must be recorded in this table.