Back to skill

Security audit

huawei-cloud-ces-aom-capacity-assessment

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Huawei Cloud capacity-assessment purpose, but its troubleshooting instructions include unsafe credentialed cloud-CLI networking workarounds.

Review before installing. Use only a Huawei Cloud account with read-only CES/AOM permissions, work on a copy of any important Excel workbook, and avoid the documented TLS-bypass/direct-IP workaround. If DNS troubleshooting is needed, prefer an approved network or DNS fix and remove any temporary hosts-file changes promptly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting-dns.md:67
Finding

TLS Certificate Verification Disabled for Authenticated Cloud API Requests

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting-dns.md, lines 67–74
Vulnerability Type: Improper Certificate Validation
Risk Level: Medium

Vulnerable snippet:

bash
## Alternative (when you prefer not to modify /etc/hosts)

- Add `--cli-endpoint` to point hcloud at the public IP (note: may fail due to certificate SNI mismatch; prefer the /etc/hosts approach):

```bash
hcloud CES ListMetrics --cli-region=cn-north-4 --namespace=SYS.ECS \
  --cli-endpoint=https://120.46.246.26 --cli-skip-secure-verify=true ...
text

### Technical Analysis

The documented fallback directs users to connect to a cloud API endpoint by IP address while passing `--cli-skip-secure-verify=true`. This disables verification of the endpoint's TLS certificate and prevents the client from confirming that it is communicating with the legitimate Huawei Cloud service.

Although the primary `/etc/hosts` approach retains the service hostname, the alternative remains an actionable installation and troubleshooting instruction. When followed, any network-positioned attacker capable of intercepting or redirecting traffic can present an arbitrary certificate without the CLI rejecting the connection.

The request is made by a configured Huawei Cloud CLI and may therefore contain signed authentication metadata. The demonstrated `ListMetrics` operation is read-only, but an interceptor can observe the authenticated request and return forged API data. If the same documented pattern is applied to the Skill's metric-collection operations, forged monitoring responses can influence the calculated capacity results and scale-out recommendations.

### Attack Path

1. The user configures `hcloud` with Huawei Cloud credentials as instructed by the Skill.
2. A DNS or SNI connectivity problem causes the user to follow the alternative troubleshooting procedure.
3. The user invokes `hcloud` with a direct-IP endpoint and `--cli-skip-secure-verify=true`.
4. An attacker with cont
...[truncated 1257 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --cli-skip-secure-verify=true from all documented commands.
  2. Require the original Huawei Cloud service hostname to remain the TLS verification and SNI hostname.
  3. Prefer a controlled DNS correction or a carefully verified /etc/hosts mapping so certificate validation remains enabled.
  4. For connectivity testing, use curl --resolve without -k, preserving both the hostname and certificate verification.
  5. Verify candidate public IP addresses through an approved DNS resolver or authoritative cloud documentation before changing host resolution.
  6. If direct-IP operation cannot preserve hostname-based certificate verification, fail securely and instruct the user to correct DNS rather than bypass TLS validation.
  7. Warn users not to generalize certificate-verification bypasses to authenticated metric-collection commands.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full capacity-assessment skill for Huawei Cloud, including cloud metric collection, analysis, prediction, and recommendation generation across 21 services. The actual code chunk does none of that. It is a narrow support module for reading and writing Excel files: parsing headers, validating required fields, inserting date columns, updating cells, saving atomically, and cleaning backup residue. The module docstring even states its boundary: 'only reads and writes, no computation, no data collection.' Because the supplied code’s primary purpose is materially different from the declared skill purpose, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The alternative command explicitly uses --cli-skip-secure-verify=true, which disables TLS certificate validation. Even though the text notes possible SNI/certificate issues, it does not clearly warn that this enables man-in-the-middle interception and defeats transport authentication, especially dangerous when contacting cloud APIs.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/capacity_cli.py (reported line 128)May include surrounding context.

python
if args.metrics:
            cmd += ["--metrics", args.metrics]
        log = progress + ".out"
        env = dict(os.environ)
        env["CAPACITY_ASSESS_CHILD"] = "1"  # child process does not clean up progress; assess-status cleans after reading done
        with open(log, "w", encoding="utf-8") as fo:
            p = subprocess.Popen(cmd, stdout=fo, stderr=subprocess.STDOUT,

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/capacity_assessment_template.xlsx!/xl/theme/theme1.xml (reported line 2)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:theme xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" name="Office 主题​​"><a:themeElements><a:clrScheme name="Office"><a:dk1><a:sysClr val="windowText" lastClr="000000"/></a:dk1><a:lt1><a:sysClr val="window" lastClr="FFFFFF"/></a:lt1><a:dk2><a:srgbClr val="1F497D"/></a:dk2><a:lt2><a:srgbClr val="EEECE1"/></a:lt2><a:accent1><a:srgbClr val="4F81BD"/></a:accent1><a:accent2><a:srgbClr val="C0504D"/></a:accent2><a:accent3><a:srgbClr val="9BBB59"/></a:accent3><a:accent4><a:srgbClr val="8064A2"/></a:accent4><a:accent5><a:srgbClr val="4BACC6"/></a:accent5><a:accent6><a:srgbClr val="F79646"/></a:accent6><a:hlink><a:srgbClr val="0000FF"/></a:hlink><a:folHlink><a:srgbClr val="800080"/></a:folHlink></a:clrScheme><a:fontScheme name="Office"><a:majorFont><a:latin typeface="Cambria"/><a:ea typeface=""/><a:cs typeface=""/><a:font script="Jpan" typeface="MS Pゴシック"/><a:font script="Hang" typeface="맑은 고딕"/><a:font script="Hans" typeface="宋体"/><a:font script="Hant" typeface="新細明體"/><a:font script="Arab" typeface="Times New Roman"/><a:font script="Hebr" typeface="Times New Roman"/><a:font script="Thai" typeface="Tahoma"/><a:font script="Ethi" typeface="Nyala"/><a:font script="Beng" typeface="Vrinda"/><a:font script="Gujr" typeface="Shruti"/><a:font script="Khmr" typeface="MoolBoran"/><a:font script="Knda" typeface="Tunga"/><a:font script="Guru" typeface="Raavi"/><a:font script="Cans" typeface="Euphemia"/><a:font script="Cher" typeface="Plantagenet Cherokee"/><a:font script="Yiii" typeface="Microsoft Yi Baiti"/><a:font script="Tibt" typeface="Microsoft Himalaya"/><a:font script="Thaa" typeface="MV Boli"/><a:font script="Deva" typeface="Mangal"/><a:font script="Telu" typeface="Gautami"/><a:font script="Taml" typeface="Latha"/><a:font script="Syrc" typeface="Estrangelo Edessa"/><a:font script="Orya" typeface="Kalinga"/><a:font script="Mlym" typeface="Kartika"/><a:font script="Laoo" typeface="DokChampa"/><a:font scrip
...[truncated 26 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes shell, file read/write, and environment-accessing capabilities but does not declare any explicit tool scope or permission boundaries. That increases the blast radius if the skill is invoked unexpectedly or composed with other agent behaviors, because operators and users cannot tell what execution powers are actually required or intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad enough to match ordinary requests about capacity, scaling, or whether ECS/RDS/CCE resources are sufficient, which can cause over-broad auto-activation. In an agent ecosystem, loose triggers increase the chance that the skill runs in the wrong context and gains shell/file access when the user did not intend to invoke it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that it writes directly back to the original Excel file and keeps no backups, but it does not present a prominent user warning or consent checkpoint before destructive modification. This creates a real risk of irreversible data loss or corruption, especially in bulk/background modes where many rows are changed automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells users to modify /etc/hosts to work around connectivity problems, which is a privileged system-level change outside the normal scope of a capacity assessment workflow. This can redirect service traffic, create persistent misconfiguration, and normalize unsafe infrastructure changes based on skill instructions rather than controlled admin procedures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file requires a specific Chinese-language error message: "该指标需要云服务维度资源ID". Under the policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These lines mandate exact Chinese output phrases such as "现有数据不支持给出建议" and use Chinese-only labels, but the document does not state that the skill is region-specific or that users can opt into this locale. This can violate language/locale policy for broadly applicable skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The required outputs include Chinese-only strings like "无法计算", "无法预测", "现有数据不支持给出建议", and "多入口实例,但单位不兼容". Because no language choice or regional justification is provided, this is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The troubleshooting guidance goes beyond normal capacity-assessment behavior by instructing operators to alter name resolution and use a direct-IP endpoint path. While presented as operational troubleshooting, these steps change network trust decisions at the host level and can route future CLI traffic to attacker-controlled or stale endpoints if copied carelessly. The skill context does not justify persistent system networking changes as part of routine capacity analysis, so this broadens the skill's effective capability in a risky way.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file instructs users to append entries to /etc/hosts without clearly warning that this is a privileged, system-wide change affecting all processes on the machine. A mistaken or stale mapping can silently redirect traffic, break future connectivity, or bypass normal DNS-based endpoint updates, creating persistent operational and security risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The verification steps instruct running an operation that writes results back into the provided Excel workbook, but they do not clearly warn the operator that the file will be modified. In this skill context, that can lead to accidental overwriting of analyst inputs or source templates during validation, especially because the expected behavior explicitly says no backup files are generated.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/capacity/collector.py (reported line 80)May include surrounding context.

python
if endpoint:
        cmd.append(f"--cli-endpoint={endpoint}")
    try:
        proc = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
    except FileNotFoundError:
        raise CollectError(f"hcloud (KooCLI) executable not found: {hcloud!r}; install it first or pass --hcloud")
    if proc.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/capacity/collector.py (reported line 186)May include surrounding context.

python
if endpoint:
        cmd.append(f"--cli-endpoint={endpoint}")
    try:
        proc = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
    except FileNotFoundError:
        raise CollectError(f"hcloud (KooCLI) executable not found: {hcloud!r}; install it first or pass --hcloud")
    if proc.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/capacity/collector.py (reported line 382)May include surrounding context.

python
all_ok = True
    for backend, cmd in probes.items():
        try:
            proc = subprocess.run(cmd, capture_output=True, text=True, timeout=60)
        except Exception as e:
            checks.append(f"{backend}: hcloud execution failed {e}")
            all_ok = False

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/capacity_cli.py (reported line 131)May include surrounding context.

python
env = dict(os.environ)
        env["CAPACITY_ASSESS_CHILD"] = "1"  # child process does not clean up progress; assess-status cleans after reading done
        with open(log, "w", encoding="utf-8") as fo:
            p = subprocess.Popen(cmd, stdout=fo, stderr=subprocess.STDOUT,
                                 start_new_session=True, env=env)
        print(json.dumps({"background": True, "pid": p.pid,
                          "progress": progress, "log": log}, ensure_ascii=False))

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes data collection, capacity calculation, prediction, and scale-out recommendation workflows. This command adds a separate file-deletion capability for .assess.log, .tmp, and .bak-* artifacts, which is not described as part of the skill's purpose and is broader than assessment itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cleanup subcommand deletes progress logs, temporary files, and all backup files associated with the workbook, but the command path contains no confirmation prompt or visible warning to the user before removal. Although the docstring describes the behavior for developers, there is no user-facing disclosure at invocation time for this destructive operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest uses Chinese-only natural-language metric names and labels across the entire file, such as at L0003 and repeated throughout, which constitutes a fixed locale choice embedded in the skill data. Because there is no indication that the skill is region-specific or that users can opt into this locale, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file hard-codes Chinese-language region labels and aliases throughout the supported mapping table and examples. Because no user opt-in or justification for a Chinese-only locale is provided, the file may violate language/locale policy for skills expected to support broader audiences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The verification steps and expected outputs rely on Chinese labels such as 云服务/云服务维度/关键指标 and later require Chinese metric names and error strings. This may constitute a language/locale policy issue because the skill behavior is effectively constrained to Chinese without documenting user choice or a justified locale limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.