Back to skill

Security audit

huawei-cloud-ces-elb-monitoring

Security checks for vulnerabilities and agentic risk

Overview

This is a real Huawei Cloud ELB monitoring skill, but its docs include risky install steps and overbroad cloud-permission guidance that users should review before installing.

Use this skill only with a narrowly scoped Huawei Cloud identity. Prefer read-only ELB/CES permissions, avoid the documented wildcard `elb:*` and `ces:*` policy, do not use IAM user listing as a connectivity test, and avoid one-line curl-to-bash or non-interactive installers unless you independently verify the source and integrity. Review and redact debug output before sharing it with support.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/iam-policies.md:281
Finding

Overly Broad Wildcard Permissions for ELB and CES Resources

Content
View full analysis

Vulnerability Details

File Location: references/iam-policies.md, lines 281–296
Vulnerability Type: Excessive cloud permissions
Risk Level: Medium

Vulnerable Snippet

json
### Scenario 2: Full Monitoring with Alarm Management

{
  "Version": "1.1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "elb:*",
        "ces:*"
      ],
      "Resource": ["*"]
    }
  ]
}

Technical Analysis

The policy recommended for “Full Monitoring with Alarm Management” grants all ELB and CES actions against all resources. This is substantially broader than the Skill’s stated monitoring purpose and the explicit read operations listed elsewhere in the project.

The wildcard actions can include resource-modifying or destructive operations unrelated to reading metrics or managing a narrowly defined set of alarms. The "Resource": ["*"] scope further removes resource-level or project-specific restrictions.

The attacker-controlled point is the Skill author’s policy guidance. The dangerous operation occurs when a user or administrator follows this guidance and attaches the policy to the identity used by the Skill. This crosses the least-privilege boundary between read-oriented ELB monitoring and unrestricted ELB/CES administration.

No evidence establishes that the author intends to abuse these privileges, so this is an excessive-permission vulnerability rather than proof of a backdoor.

Attack Path

  1. A user requests full monitoring or alarm-management capabilities.
  2. The Agent refers the user to the policy in references/iam-policies.md.
  3. The user or cloud administrator creates and attaches the documented policy.
  4. The Skill’s identity receives every ELB and CES action over every applicable resource.
  5. A compromised CLI, malicious follow-up instruction, or unintended command can then use those privileges to modify resources beyond the monitoring task’s authorization scope.

Impact Assessment

The affected iden ...[truncated 430 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace elb:* and ces:* with an explicit allowlist of operations required by the workflow.
  • Preserve the existing read-only ELB and CES permissions for monitoring.
  • If alarm creation is supported, add only the exact create, update, or delete actions that the user explicitly requests.
  • Separate read-only monitoring and alarm-management policies so users do not need write permissions for ordinary metric queries.
  • Restrict resources by project, account, alarm, or ELB identifiers wherever Huawei Cloud IAM supports resource-level scoping.
  • Document a confirmation step before any alarm or resource mutation.
  • Remove the wildcard policy example to prevent it from being copied into production.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/verification-method.md:29
Finding

Unrelated IAM User Enumeration During Connectivity Verification

Content
View full analysis

Vulnerability Details

File Location: references/verification-method.md, lines 29–35
Vulnerability Type: Unnecessary access to cloud identity metadata
Risk Level: Medium

Vulnerable Snippet

bash
3. **Test Basic Connectivity**

   ```bash
   hcloud IAM KeystoneListUsers  --cli-region=<region-id>

Expected Result: User information returned without permission errors.

text

### Technical Analysis

The Skill is intended to monitor ELB resources through CES, but its environment-verification procedure instructs the Agent to enumerate IAM users. IAM directory data is unrelated to determining whether ELB and CES monitoring APIs are reachable.

The input and behavior are controlled by the Skill instructions rather than by a user’s explicit request to inspect IAM users. The dangerous operation is an authenticated IAM API call that retrieves account user information. This crosses the authorization-purpose boundary because cloud credentials supplied for ELB monitoring are used to query unrelated identity metadata.

The command does not itself grant additional IAM permissions and will fail if the current identity lacks the necessary access. However, when the identity already has that access, the procedure unnecessarily exposes IAM user information in command output or the Agent session. There is no evidence of covert transmission or malicious intent.

### Attack Path

1. A user invokes the Skill for ELB monitoring.
2. The Agent follows the documented environment-verification procedure.
3. The Agent executes `hcloud IAM KeystoneListUsers` using the user’s configured cloud identity.
4. If that identity can list IAM users, account user metadata is returned.
5. The unrelated identity data becomes visible in the terminal output or Agent context even though the user only authorized ELB monitoring.

### Impact Assessment

The command may disclose IAM user metadata available to the configured identity, increasing exposure of account-directory in
...[truncated 288 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace hcloud IAM KeystoneListUsers with a minimal operation already required by the Skill, such as:
    • hcloud ELB ListLoadBalancers --cli-region=<region-id> --limit=1
    • hcloud CES ListMetrics --namespace="SYS.ELB" --cli-region=<region-id> --limit=1
  • Do not retrieve IAM users, roles, policies, or other account-directory information during ELB monitoring verification.
  • Align verification commands with the documented minimum ELB and CES read-only permissions.
  • Ensure verification output contains only information necessary to establish CLI availability, authentication status, and access to the target monitoring services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (54)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file is a full KooCLI installation and management guide, which materially exceeds the stated scope of an ELB/CES monitoring skill. In a skill package, this scope mismatch can normalize or induce installation of a broad cloud administration tool, increasing the chance that the agent or user is guided into unnecessary privileged actions and wider account access.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This line downloads a remote shell script and executes it immediately. That is a classic high-risk supply-chain pattern because any compromise of the source, transport assumptions, or script contents results in arbitrary code execution on the host.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 21)May include surrounding context.

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The non-interactive variant is even riskier because it both executes remote code and suppresses user confirmation. This combines supply-chain exposure with reduced operator oversight, making accidental or silent compromise easier.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 24)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The Dockerfile bakes remote-script execution into image build steps, embedding trust in a mutable external script into automated builds. That can poison CI/CD pipelines or produce compromised images reproducibly across environments.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 118)May include surrounding context.

dockerfile
FROM ubuntu:latest
RUN apt-get update -y && apt-get install curl -y
RUN curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y
WORKDIR /workspace
ENTRYPOINT ["/usr/local/bin/hcloud"]

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

This troubleshooting path again recommends fetching and executing an external script, here as an alternative install location flow. Repetition of this pattern increases the chance it will be copied blindly and normalizes unsafe install practices.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 181)May include surrounding context.

sudo bash ./hcloud_install.sh

Or install to user directory

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -d ~/.local/bin

text

#### Command Not Found

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The update section recommends reinstalling via fetched remote script, extending the same supply-chain risk into maintenance operations. Since updates are repeated over time, this compounds exposure compared with a one-time install.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 230)May include surrounding context.

hcloud update

Or reinstall latest version

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Uninstall KooCLI

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

Although not parameter abuse in the catastrophic sense, this command does perform destructive deletion of a system binary with sudo. In a documentation context it is acceptable only with clear warnings; absent that, it can still cause unintended disruption if copied blindly.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 237)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This line uses 'sudo rm -rf' against a product directory, which is inherently destructive and privileged. The command is not malicious on its face, but in copy-paste docs it can be hazardous if path assumptions differ or users do not verify the target.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 238)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This line uses 'sudo rm -rf' against a product directory, which is inherently destructive and privileged. The command is not malicious on its face, but in copy-paste docs it can be hazardous if path assumptions differ or users do not verify the target.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 238)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deleting '~/.hcloud/' removes user-local configuration and potentially credentials or state. In the absence of warnings and backup guidance, this presents a real data-loss risk even though the command is scoped.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 239)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deleting '~/.hcloud/' removes user-local configuration and potentially credentials or state. In the absence of warnings and backup guidance, this presents a real data-loss risk even though the command is scoped.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 239)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The cache deletion command is targeted, but still an irreversible recursive removal. Its impact is lower than config deletion, yet it may erase useful local artifacts and should be presented with caution.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 251)May include surrounding context.

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The cache deletion command is targeted, but still an irreversible recursive removal. Its impact is lower than config deletion, yet it may erase useful local artifacts and should be presented with caution.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 251)May include surrounding context.

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

Fetching and running an external script in one command is a direct remote-script execution pattern and a well-known high-risk supply-chain anti-pattern. The skill context makes this more dangerous because users seeking cloud troubleshooting help are likely to copy-paste commands with elevated trust.

Content

Scanner excerpt · references/troubleshooting-guide.md (reported line 46)May include surrounding context.

md
# See references/cli-installation-guide.md for detailed instructions

# One-click installation (recommended, all platforms)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Or install manually on Linux (AMD 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"

External Script Fetching

High
Category
Supply Chain
Confidence
87% confidence
Finding

This sequence fetches an external archive, extracts it, and then installs the resulting binary into a trusted path. Although not as severe as direct script execution, it still relies on unauthenticated trust in downloaded executable content and becomes dangerous when followed by privileged installation.

Content

Scanner excerpt · references/troubleshooting-guide.md (reported line 49)May include surrounding context.

md
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Or install manually on Linux (AMD 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The support workflow tells users to run the CLI in debug mode before creating a support ticket, but does not warn that debug logs can expose credentials, tokens, request signatures, resource IDs, or other sensitive metadata. Users may inadvertently disclose secrets to third parties or ticketing systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Overly broad trigger phrases like 'CES' or generic monitoring terms can cause the agent to invoke this skill for requests outside Huawei ELB monitoring, increasing the chance of unintended command execution against cloud resources. In a cloud CLI skill, overbroad activation is more dangerous because it may prompt unnecessary enumeration of load balancers, listeners, alarms, or metrics in a user environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to download and immediately execute a remote shell script, including a non-interactive mode that suppresses user confirmation. That pattern is dangerous because it delegates execution trust to network-delivered code without integrity verification, review, or explicit risk warning.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The command fetches code from an external host and saves it locally for execution. External transmission itself is expected for installation, but in this context it directly feeds into code execution, making network trust and tampering risks meaningful.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 21)May include surrounding context.

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The non-interactive 'skip confirmation' mode removes a human review checkpoint for installation of remotely sourced code. In agent-assisted or copy-paste workflows, this increases the chance of unattended installation into the wrong environment or with unintended privileges.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 23)May include surrounding context.

Download and run official installation script (interactive)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

This line instructs use of sudo to place a downloaded executable into a system path. The act is not inherently malicious, but it elevates trust in the downloaded binary and can affect all users on the host if the artifact is compromised.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 56)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

This repeats the privileged installation pattern for the ARM build. The security concern is the same: a downloaded binary is granted system-wide execution via root-assisted placement.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 61)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

The macOS Intel installation path also uses sudo to install a downloaded binary globally. In the context of a monitoring skill, this is more privilege than should be normalized unless absolutely necessary.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 82)May include surrounding context.

md
# Intel chips (AMD 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-amd64.tar.gz"
tar -zxvf huaweicloud-cli-mac-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# Apple Silicon (ARM 64-bit)
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

This is the same privileged global install pattern for Apple Silicon systems. The risk is system-wide exposure if the downloaded artifact is malicious or replaced.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 87)May include surrounding context.

Apple Silicon (ARM 64-bit)

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-mac-arm64.tar.gz" tar -zxvf huaweicloud-cli-mac-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 3. Windows Systems

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.exposed_secret_literal

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/cli-installation-guide.md:238

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/iam-policies.md:248