Back to skill

Security audit

huawei-cloud-cli-guidance

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Huawei Cloud CLI guide, but it contains risky install and cloud-deployment examples that users should review before use.

Install only if you specifically need Huawei Cloud KooCLI help. Before following commands, avoid non-interactive remote installer execution unless you independently trust and verify the source, replace all example passwords with unique generated secrets or SSH keys, restrict SSH ingress to your own approved IP range, keep SSH host-key checking enabled, and confirm every cloud resource creation/deletion step explicitly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/common-workflows.md:25
Finding

Public ECS Deployment Uses a Known Root Password with Internet-Wide SSH Access

Content
View full analysis

Vulnerability Details

File Location: references/common-workflows.md:25-43, references/common-workflows.md:73-80, references/common-workflows.md:93-105, references/common-workflows.md:350-355; related example in references/core-commands.md:53-64
Vulnerability Type: Hardcoded predictable administrative credential and excessive network exposure
Risk Level: High

Vulnerable Code

bash
# 5. Create instance
hcloud ECS CreateServers \
  --server.name=my-instance \
  --server.imageRef=<image-id> \
  --server.flavorRef=ac8.large.2 \
  --server.vpcid=<vpc-id> \
  --server.subnet_id=<subnet-id> \
  --server.security_groups.1.id=<sg-id> \
  --server.adminPass=MyP@ssw0rd123! \
  --server.publicip.eip.bandwidth.sharetype=PER \
  --server.publicip.eip.bandwidth.size=5 \
  --server.publicip.eip.bandwidth.charge_mode=bandwidth \
  --cli-region=cn-north-4

# 7. Verify SSH connection
sshpass -p 'MyP@ssw0rd123!' ssh -o StrictHostKeyChecking=no root@<public-ip> "echo OK"

The same workflow creates an Internet-wide SSH rule:

bash
hcloud VPC CreateSecurityGroupRule/v3 \
  --security_group_id=<sg-id> \
  --security_group_rule.direction=ingress \
  --security_group_rule.protocol=tcp \
  --security_group_rule.multiport=22 \
  --security_group_rule.remote_ip_prefix=0.0.0.0/0 \
  --security_group_rule.description="Allow SSH" \
  --cli-region=cn-north-4

The document subsequently reinforces the literal as an example:

markdown
1. Use strong passwords (e.g., MyP@ssw0rd123!)

A related core command also embeds a fixed administrative password:

bash
hcloud ECS CreateServers \
  --server.name=my-instance \
  --server.imageRef=img-ubuntu-22-04 \
  --server.flavorRef=ac8.large.2 \
  --server.vpcid=vpc-12345678 \
  --server.subnet_id=subnet-12345678 \
  --server.adminPass=MySecurePass123! \
  --server.security_groups.1.id=sg-12345678 \
  --server.publicip.eip.bandwidth.sharetype=PER \
  --server.publicip.eip
...[truncated 2231 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace every literal administrative password with a mandatory placeholder that cannot be mistaken for a usable credential.
  2. Prefer SSH public-key authentication and disable password-based root login.
  3. If a password is unavoidable, generate a unique high-entropy value for each instance through an approved secret-management mechanism. Do not place it in command history, source documents, logs, or Agent output.
  4. Restrict SSH ingress to a user-approved management CIDR, VPN, bastion host, or zero-trust access path. Do not use 0.0.0.0/0 as the default.
  5. Separate resource creation from network exposure and require the user to confirm the exact source CIDR before applying the security-group rule.
  6. Remove MyP@ssw0rd123! and MySecurePass123! from all examples, including the statement that characterizes the former as a strong-password example.
  7. Add post-deployment validation that checks for Internet-wide administrative ports and rejects or prominently warns about such configurations.

T09 · Insecure Skill Coding Practices

Warning
Location
references/common-workflows.md:279
Finding

SSH Diagnostic Workflows Disable Host Authentication While Transmitting Root Passwords

Content
View full analysis

Vulnerability Details

File Location: references/common-workflows.md:42-43, references/common-workflows.md:279-318
Vulnerability Type: SSH host-verification bypass enabling credential interception
Risk Level: Medium

Vulnerable Code

bash
# 7. Verify SSH connection
sshpass -p 'MyP@ssw0rd123!' ssh -o StrictHostKeyChecking=no root@<public-ip> "echo OK"

The deep-diagnostic workflow repeats this pattern:

bash
# 1. Basic connection test
sshpass -p '<password>' ssh -o StrictHostKeyChecking=no root@<ip> "echo OK"

Technical Analysis

StrictHostKeyChecking=no instructs SSH to accept a host without requiring trusted verification of its identity. The same commands use sshpass to authenticate as root with a password. Consequently, a network endpoint that can intercept, redirect, or impersonate the intended server can present an arbitrary SSH host key and receive the authentication attempt.

The attacker-controlled point is the SSH endpoint and its presented host key. The crossed trust boundary is between an untrusted network endpoint and the user-authorized ECS host: the workflow treats the former as the latter without authenticating it.

The diagnostic purpose does not require disabling host verification. The command weakens SSH's server-authentication security precisely while handling an administrative secret.

Attack Path

  1. A user or Agent invokes the documented SSH verification workflow against an ECS public IP.
  2. A network attacker obtains a position capable of redirecting or intercepting the connection, such as through routing, DNS, proxy, or local-network manipulation.
  3. The attacker presents an SSH service with an untrusted host key.
  4. Because StrictHostKeyChecking=no is set, the client does not stop for trusted host-key validation.
  5. The workflow submits the root password to the impersonating endpoint.
  6. The attacker captures the credential and uses it to authenticate to the actual ECS ...[truncated 486 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove -o StrictHostKeyChecking=no from every SSH example.
  2. Obtain the ECS host-key fingerprint through a trusted channel and verify it before the first connection.
  3. Prepopulate a dedicated known_hosts file with the verified key and invoke SSH with strict checking enabled.
  4. Prefer short-lived SSH keys or certificates over passwords and remove sshpass from the workflow.
  5. If automated verification is required, use options equivalent to StrictHostKeyChecking=yes and a controlled UserKnownHostsFile.
  6. Treat a changed or unknown host key as a blocking security error rather than automatically accepting it.
  7. Avoid placing administrative passwords directly on the command line, where they may be exposed through shell history or process inspection.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (59)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: huawei-cloud-cli-guidance
description: >-
  Provides guidance for Huawei Cloud KooCLI command-line tool operations.
  Covers KooCLI installation, IAM authentication configuration, access credential configuration, command construction, common error troubleshooting.
  Use this skill when users ask about any cloud-related services or wants to operate Huawei Cloud services from the terminal.
  Triggers: Huawei Cloud, huaweiyun, "华为云","华为cli", "命令行", KooCLI, hcloud, huaweiyunCLI, Huawei Cloud command line, OBS, ECS, VPC, "云", yun, huaweiyun tool, huawei tool, "华为云工具", "云工具", "工具"

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes extremely broad terms such as "云", "yun", "工具", and generic cloud service names, which can cause this skill to activate for many unrelated requests. Because the skill is allowed to use Bash and includes installation/authentication guidance, unintended invocation increases the chance that users are steered into credential handling or shell actions outside the intended Huawei Cloud context.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to fetch a shell script over the network and execute it immediately with bash, without checksum, signature, or provenance verification. This is a classic supply-chain and remote code execution risk: if the hosting endpoint, DNS, TLS trust chain, or object is compromised, arbitrary code will run on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

bash
# Universal for all platforms
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The non-interactive installer repeats the same unsafe pattern of downloading and executing a remote script directly, but removes even more user friction before execution. In this skill context, that is especially risky because the skill is designed to operate in terminal sessions and may be invoked broadly, making accidental or unquestioned execution more likely.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text
##### After installation completes, check if local installation was successful.
Important: No additional operations allowed!!! Any file content changes must obtain user permission.

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/cli-troubleshooting.md (reported line 247)May include surrounding context.

hcloud --help

text

### Step 3: Enable Debug Mode
```bash
# Enable detailed logs
hcloud <SERVICE> <OPERATION> --cli-debug=true --cli-region=cn-north-4

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · references/core-commands.md (reported line 214)May include surrounding context.

md
hcloud EVS AttachVolume \
  --volume_id=vol-12345678 \
  --server_id=i-12345678 \
  --device=/dev/vdb \
  --cli-region=cn-north-4

# Detach volume

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The guide explicitly tells users to download a remote shell script and execute it immediately. This is dangerous because it delegates trust to a mutable network resource; compromise of the host, object store, CDN, or transport path could result in arbitrary code execution on the user's machine.

Content

Scanner excerpt · references/installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The non-interactive fetch-and-execute variant is even riskier because it both runs a remote script and suppresses confirmation prompts. In an installation guide, this is likely to be copied directly, increasing the chance of silent arbitrary code execution.

Content

Scanner excerpt · references/installation-guide.md (reported line 20)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

External Script Fetching

High
Category
Supply Chain
Confidence
92% confidence
Finding

The Dockerfile bakes a remote fetched script directly into the image build, creating a supply-chain risk for every downstream image consumer. Because the script is unpinned and unverified, rebuilds may execute different code over time and can silently import malicious behavior.

Content

Scanner excerpt · references/installation-guide.md (reported line 105)May include surrounding context.

Custom Image

dockerfile
FROM ubuntu:latest
RUN apt-get update -y && apt-get install curl -y
RUN curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y
WORKDIR /workspace
ENTRYPOINT ["/usr/local/bin/hcloud"]

External Script Fetching

High
Category
Supply Chain
Confidence
88% confidence
Finding

This user-directory installation path still uses a fetched external script executed immediately without integrity checks. Although it avoids root, it still enables arbitrary code execution in the user's context and may alter shell configuration or credentials.

Content

Scanner excerpt · references/installation-guide.md (reported line 160)May include surrounding context.

sudo bash ./hcloud_install.sh

Or install to user directory

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -d ~/.local/bin

text

#### Command Not Found

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

Recommending reinstallation via a fresh curl-and-bash flow during updates reintroduces the same arbitrary code execution risk after initial setup. It also trains users to trust mutable network-delivered scripts for ongoing maintenance.

Content

Scanner excerpt · references/installation-guide.md (reported line 205)May include surrounding context.

hcloud update

Or reinstall latest version

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Uninstall KooCLI

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Deleting /usr/local/bin/hcloud is a legitimate uninstall action, but it is still a destructive command operating in a privileged system path. In documentation intended for command-line execution, destructive commands should be clearly framed to prevent accidental misuse.

Content

Scanner excerpt · references/installation-guide.md (reported line 211)May include surrounding context.

Uninstall KooCLI

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

sudo rm -rf /usr/local/hcloud/ is a powerful recursive deletion command in a privileged location. Even though the path is specific, the combination of sudo and rm -rf poses meaningful risk if copied incorrectly, edited, or if the documented path changes over time.

Content

Scanner excerpt · references/installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

sudo rm -rf /usr/local/hcloud/ is a powerful recursive deletion command in a privileged location. Even though the path is specific, the combination of sudo and rm -rf poses meaningful risk if copied incorrectly, edited, or if the documented path changes over time.

Content

Scanner excerpt · references/installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Removing ~/.hcloud/ recursively can erase credentials, profiles, and local state in addition to cache. In the context of a cloud CLI guide, this is more dangerous because users may rely on those profiles across multiple environments.

Content

Scanner excerpt · references/installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Removing ~/.hcloud/ recursively can erase credentials, profiles, and local state in addition to cache. In the context of a cloud CLI guide, this is more dangerous because users may rely on those profiles across multiple environments.

Content

Scanner excerpt · references/installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.hcloud/cache/ is a destructive cleanup command that can remove data without confirmation. While scoped to cache, documentation should still warn users and explain the effect before recommending recursive deletion.

Content

Scanner excerpt · references/installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

rm -rf ~/.hcloud/cache/ is a destructive cleanup command that can remove data without confirmation. While scoped to cache, documentation should still warn users and explain the effect before recommending recursive deletion.

Content

Scanner excerpt · references/installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/core-commands.md (reported line 351)May include surrounding context.

Error Debugging

bash
# Enable debug mode
hcloud <SERVICE> <OPERATION> \
  --cli-debug=true \
  --cli-region=cn-north-4

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/parameter-format.md (reported line 346)May include surrounding context.

Error Debugging

bash
# Enable debug mode
hcloud <SERVICE> <OPERATION> \
  --cli-debug=true \
  --cli-region=cn-north-4

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file instructs the agent to prioritize and fully use this document for all KooCLI issues, while the document is written entirely in English despite having multilingual triggers and a likely Chinese-user context. There is no instruction to ask the user for preferred language or locale, nor an explicit opt-in for response language.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 440)May include surrounding context.

md
### Authentication Management
1. **Use Profile mode** for long-term session management
2. **Create independent Profiles** for different environments (dev/test/prod)
3. **Regularly rotate AK/SK**, avoid using the same credentials long-term
4. **Use IAM users instead of main account** for daily operations

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-troubleshooting.md (reported line 12)May include surrounding context.

md
| Error | Cause | Solution |
|-------|-------|----------|
| `hcloud: command not found` | KooCLI not installed or not in PATH | `sudo mv hcloud /usr/local/bin/` |
| `Permission denied` | No execution permission | `chmod +x /usr/local/bin/hcloud` |
| `hcloud --version` no output | Known bug | Use `hcloud --help` |
| SSL/TLS certificate error | System CA certificates outdated | `apt update && apt install ca-certificates` |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation-guide.md (reported line 49)May include surrounding context.

md
| Error | Cause | Solution |
|-------|-------|----------|
| `hcloud: command not found` | KooCLI not installed or not in PATH | `sudo mv hcloud /usr/local/bin/` |
| `Permission denied` | No execution permission | `chmod +x /usr/local/bin/hcloud` |
| `hcloud --version` no output | Known bug | Use `hcloud --help` |
| SSL/TLS certificate error | System CA certificates outdated | `apt update && apt install ca-certificates` |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation-guide.md (reported line 73)May include surrounding context.

md
| Error | Cause | Solution |
|-------|-------|----------|
| `hcloud: command not found` | KooCLI not installed or not in PATH | `sudo mv hcloud /usr/local/bin/` |
| `Permission denied` | No execution permission | `chmod +x /usr/local/bin/hcloud` |
| `hcloud --version` no output | Known bug | Use `hcloud --help` |
| SSL/TLS certificate error | System CA certificates outdated | `apt update && apt install ca-certificates` |

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.exposed_secret_literal

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/installation-guide.md:212

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/core-commands.md:254