Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md # Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for managing CloudRobo assets, but it handles powerful cloud credentials and asset deletion while documenting insecure SSL and credential practices that need review before installation.
Install only if you intend to let the agent manage CloudRobo assets with credentials that can read, create, update, delete, import, export, and transfer asset data. Use least-privilege AK/SK credentials, protect ~/.cloudrobo/config.yaml if used, avoid traffic logging, keep SSL verification enabled, and require explicit confirmation for delete, batch-delete, import, and export operations.
Referenced artifact was not completely inspected
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets
Referenced artifact was not completely inspected
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets
Referenced artifact was not completely inspected
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| show-asset | `--asset-id <id>` | `client.show_asset(asset_id)` | `GET /v1/assets/{asset_id}` |
| delete-asset | `--asset-id <id> [--dry-run]` | `client.delete_asset(asset_id)` | `DELETE /v1/assets/{asset_id}` |
| batch-delete-assets | `--asset-ids "id1,id2" [--dry-run]` | `client.batch_delete_assets({"asset_ids": [...]})` | `POST /v1/assets/batch-delete` |
### Version Management 版本管理
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| show-version | `--asset-id <id> --version-id <vid>` | `client.show_asset_version(asset_id, version_id)` | `GET /v1/assets/{asset_id}/versions/{version_id}` |
| delete-version | `--asset-id <id> --version-id <vid> [--dry-run]` | `client.delete_asset_version(asset_id, version_id)` | `DELETE /v1/assets/{asset_id}/versions/{version_id}` |
| batch-delete-versions | `--asset-id <id> --version-ids "v1,v2" [--dry-run]` | `client.batch_delete_asset_versions(asset_id, {"version_ids": [...]})` | `POST /v1/assets/{asset_id}/versions/batch-delete` |
### Tag Management 标签管理
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| add-tags | `--asset-id <id> --tags "t1,t2" [--dry-run]` | `client.add_tags(asset_id, tags)` | `POST /v1/assets/{asset_id}/tags` |
| delete-tag | `--asset-id <id> --tag <tag> [--dry-run]` | `client.delete_tag(asset_id, tag)` | `DELETE /v1/assets/{asset_id}/tags/{tag}` |
| list-tags | `--language <zh\|en> [--type] [--sub-type]` | `client.list_all_tags(language, type, sub_type)` | `GET /v1/asset-tags` |
### Action Management Action管理
Referenced artifact was not completely inspected
- [Acceptance Criteria](references/acceptance-criteria.md) — Acceptance criteria
Referenced artifact was not completely inspected
Test cases: see `templates/test-vars.json` for the full list covering all asset operations.
The troubleshooting guidance recommends disabling SSL verification via CLOUDROBO_VERIFY_SSL=false with only a minimal 'debug only' note and no warning about man-in-the-middle attacks or credential theft. Because this CLI uses AK/SK credentials and performs asset import/export over the network, disabling certificate validation could expose authentication secrets and transmitted data to interception or tampering.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Agent->>CLI: delete-asset --asset-id
CLI->>SDK: delete_asset(asset_id)
SDK->>API: DELETE /v1/assets/{asset_id}
API-->>SDK: deleted
SDK-->>CLI: success
CLI-->>Agent: cleanup done
The description lists many natural-language triggers such as "tag management," "permission check," and "marketplace search" without defining when the skill should or should not activate. Because this is a manifest-style section in a markdown file, the broad phrases may overlap with common requests and there are no negative examples or scope constraints to prevent unintended invocation.
The guide instructs users to place long-lived AK/SK credentials in environment variables and a plaintext config file without warning about secret exposure risks such as shell history leakage, process environment disclosure, backups, or overly permissive file permissions. In a cloud asset-management CLI, compromise of these credentials could allow unauthorized access to repositories, assets, imports/exports, and related cloud resources.
Documenting VERIFY_SSL=false as a troubleshooting measure normalizes an unsafe default or unsafe operational mode for a networked cloud CLI. In this skill's context, the danger is elevated because the tool manages cloud assets and uses AK/SK credentials, so users may disable transport validation during sensitive operations and expose themselves to MITM attacks and malicious endpoint impersonation.
| `OBS upload failed` | Check `cloudrobo-obs` endpoint configuration and DNS reachability |
| `FileNotFoundError` | `import-asset` requires `local_path` to exist |
| `No versions found` | `export-asset` requires at least one version |
| SSL verification errors | Set `CLOUDROBO_VERIFY_SSL=false` (debug only) |
## Environment Variables 环境变量
The markdown describes delete-asset and shows a successful cleanup flow, but it does not include any warning that the operation is destructive or may remove user-managed assets. The API summary also lists multiple delete and batch-delete endpoints without any caution about data loss or reversibility.
This markdown explicitly documents reading from local paths, uploading folders to object storage, downloading content, creating directories, and writing README.md files, but it provides no warning about modifying local files or transferring data to remote storage. For markdown files, the expected disclosure is a warning when behavior can affect user data, privacy, or system integrity.
Line L12 specifies the friendly message "该资产版本没有血缘关系", which hardcodes a Chinese response for users regardless of their language preference. This is a language-policy issue because the file does not indicate any user choice or justified region-specific restriction.
The documentation explicitly describes disabling SSL verification via CLOUDROBO_VERIFY_SSL=false, which can normalize an insecure practice. If users follow this guidance outside tightly controlled debugging scenarios, they become vulnerable to man-in-the-middle attacks, especially because this skill uses AK/SK-signed requests and may also enable traffic logging that could expose sensitive material.
- **Signing mechanism** — APIG HMAC-SHA256 signs each request with a timestamp to prevent
replay attacks
- **Proxy support** — Optional HTTP/HTTPS proxy can be configured for network isolation
- **SSL verification** — Can be disabled for debugging (`CLOUDROBO_VERIFY_SSL=false`) but
should be enabled in production
- **Traffic logging** — `CLOUDROBO_LOG_TRAFFIC=true` enables request/response logging for
debugging; disable in production to avoid credential leakage in logs
This markdown file is entirely written in Chinese and does not indicate that users may access an English alternative or choose their preferred language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
The verification steps require specific Chinese section headers such as '概述', '前置条件', and others, which effectively enforces a particular language format. The file does not indicate that this locale requirement is optional, user-selected, or justified as a region-specific constraint.
The test case explicitly uses --language zh in the CLI path and language='zh' in the SDK path, forcing a specific language/locale. This matches the locale policy violation category because the script does not offer an opt-in, fallback, or documented region-specific justification.
Lines L047-L048 specify verification commands using --language zh, which imposes a specific language setting in natural-language guidance. The file does not indicate that this is optional, user-selected, or required for a region-specific compliance reason.
The configuration example hard-codes region: cn-southwest-2 without explaining that this is only an example or instructing users to choose an appropriate region. The policy category applies to locale/region constraints that are imposed without opt-in or clear justification.
The heading mixes English with Chinese ("边界情况"), which imposes a specific language in the skill content without any visible opt-in or explanation that the skill is intended for a Chinese-speaking audience. Under the policy, locale or language constraints should be optional or clearly justified.
The headings and labels are presented bilingually with Chinese prominently embedded throughout the document, but there is no indication that this language choice is optional, user-selectable, or required for a specific regional compliance context. Under the policy rule, forcing a specific language or locale without opt-in can be a natural-language policy concern.
The text explicitly limits the language field to zh or en and does not explain why only those locales are permitted. This is a locale policy concern because it constrains language selection without documented justification or broader opt-in framing.
No suspicious patterns detected.