Back to skill

Security audit

huawei-cloud-cdn-traffic-anomaly-analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Huawei Cloud CDN traffic analysis skill with disclosed cloud access and clear write-operation refusals, though users should use least-privilege credentials.

Install only if you intend to let an agent query Huawei Cloud CDN billing mode, domain inventory, and traffic metrics. Use a dedicated least-privilege IAM user, avoid pasting AK/SK into chat, configure credentials only on a trusted machine, and prefer explicit read-only CDN permissions if your organization can define them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description promises a full CDN anomaly analysis workflow, including querying CDN/domain data and comparing current traffic with historical baselines to identify abuse. The code does none of that. Its sole function is generating timestamp ranges and baseline windows, which may be a small helper component for a larger analysis pipeline, but by itself it does not implement the declared primary purpose. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
>
> If a user attempts to provide AK/SK directly (e.g., "my AK is xxx, SK is yyy"):
>
> - **Stop immediately** - Do not execute any commands
> - **Politely refuse** and return the following message:
>
> ```

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L33 requires all API calls to use --cli-region=cn-north-1, which is a locale/region constraint expressed in natural language. The file does not indicate that this is optional, user-selected, or justified as a region-specific skill, so it may violate the policy against forcing a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to run hcloud configure and enter long-lived AK/SK credentials, but it provides no warning about secure handling, storage, least-privilege scoping, or avoiding credential exposure in shared terminals and logs. In a cloud administration context, omitted secret-handling guidance increases the risk of credential leakage and subsequent unauthorized access to Huawei Cloud resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The note 'Always use --cli-region=cn-north-1 for CDN APIs' imposes a fixed region selection in natural language. Under the policy criteria, forcing a specific locale/region without opt-in or explicit justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file repeatedly instructs users to calculate timestamps aligned to UTC+8 midnight, which imposes a specific locale/timezone behavior in natural language. No opt-in, alternative timezone handling, or region-specific justification is provided, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script hard-codes TZ_CST = timezone(timedelta(hours=8)) and documents all output as UTC+8, which imposes a specific locale/time interpretation on all users. Because there is no option to select another timezone or explanation that the tool is intentionally region-specific, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document states the region parameter is required and 'always use cn-north-1', which imposes a fixed locale/region choice in the skill behavior. Although technical context is given, it does not present this as a user choice or clearly frame it as an organizational language/locale policy exception.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

The recommended IAM permission cdn:*:query* is broader than necessary and may grant access to all present and future CDN query-class APIs, not just the four operations this skill needs. Even though the skill is read-only, broad query permissions can expose additional metadata or account inventory beyond the minimum needed, increasing blast radius if the agent, account, or policy is misused.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
Ensure the IAM user has the required permissions. See [references/iam-policies.md](references/iam-policies.md) for details.

**Minimum required permissions:**

- `cdn:*:query*` — All CDN query-class actions used by this skill (`ListDomains/v2`, `ShowChargeModes`, `ShowDomainStats/v2`, `ShowBandwidthCalc`)
- `cdn:configuration:queryDomains` — List CDN domains (listed explicitly alongside the wildcard)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L008 specifies --cli-region=cn-north-1 as a fixed input parameter. This is a natural-language locale/region constraint presented without opt-in, alternatives, or explanation that the skill is region-specific, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The guidance says to "Always use --cli-region=cn-north-1" and presents this as a universal rule. Under the policy criteria, forcing a specific region/locale without opt-in or an explicit justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.