Back to skill

Security audit

huawei-cloud-cloudrobo-asset

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing CloudRobo assets, but it handles powerful cloud credentials and asset deletion while documenting insecure SSL and credential practices that need review before installation.

Install only if you intend to let the agent manage CloudRobo assets with credentials that can read, create, update, delete, import, export, and transfer asset data. Use least-privilege AK/SK credentials, protect ~/.cloudrobo/config.yaml if used, avoid traffic logging, keep SSL verification enabled, and require explicit confirmation for delete, batch-delete, import, and export operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

md
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 371)May include surrounding context.

md
# Either --repository-id OR --catalog-id filters the list. Full parameter list: see references/api-paths.md → List Assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| show-asset | `--asset-id <id>` | `client.show_asset(asset_id)` | `GET /v1/assets/{asset_id}` |
| delete-asset | `--asset-id <id> [--dry-run]` | `client.delete_asset(asset_id)` | `DELETE /v1/assets/{asset_id}` |
| batch-delete-assets | `--asset-ids "id1,id2" [--dry-run]` | `client.batch_delete_assets({"asset_ids": [...]})` | `POST /v1/assets/batch-delete` |

### Version Management 版本管理

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| show-version | `--asset-id <id> --version-id <vid>` | `client.show_asset_version(asset_id, version_id)` | `GET /v1/assets/{asset_id}/versions/{version_id}` |
| delete-version | `--asset-id <id> --version-id <vid> [--dry-run]` | `client.delete_asset_version(asset_id, version_id)` | `DELETE /v1/assets/{asset_id}/versions/{version_id}` |
| batch-delete-versions | `--asset-id <id> --version-ids "v1,v2" [--dry-run]` | `client.batch_delete_asset_versions(asset_id, {"version_ids": [...]})` | `POST /v1/assets/{asset_id}/versions/batch-delete` |

### Tag Management 标签管理

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 264)May include surrounding context.

md
| Command | Key Params | SDK Method | API |
|---------|-----------|------------|-----|
| add-tags | `--asset-id <id> --tags "t1,t2" [--dry-run]` | `client.add_tags(asset_id, tags)` | `POST /v1/assets/{asset_id}/tags` |
| delete-tag | `--asset-id <id> --tag <tag> [--dry-run]` | `client.delete_tag(asset_id, tag)` | `DELETE /v1/assets/{asset_id}/tags/{tag}` |
| list-tags | `--language <zh\|en> [--type] [--sub-type]` | `client.list_all_tags(language, type, sub_type)` | `GET /v1/asset-tags` |

### Action Management Action管理

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 370)May include surrounding context.

md
- [Acceptance Criteria](references/acceptance-criteria.md) — Acceptance criteria

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
Test cases: see `templates/test-vars.json` for the full list covering all asset operations.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The troubleshooting guidance recommends disabling SSL verification via CLOUDROBO_VERIFY_SSL=false with only a minimal 'debug only' note and no warning about man-in-the-middle attacks or credential theft. Because this CLI uses AK/SK credentials and performs asset import/export over the network, disabling certificate validation could expose authentication secrets and transmitted data to interception or tampering.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 91)May include surrounding context.

md
Agent->>CLI: delete-asset --asset-id
    CLI->>SDK: delete_asset(asset_id)
    SDK->>API: DELETE /v1/assets/{asset_id}
    API-->>SDK: deleted
    SDK-->>CLI: success
    CLI-->>Agent: cleanup done

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description lists many natural-language triggers such as "tag management," "permission check," and "marketplace search" without defining when the skill should or should not activate. Because this is a manifest-style section in a markdown file, the broad phrases may overlap with common requests and there are no negative examples or scope constraints to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to place long-lived AK/SK credentials in environment variables and a plaintext config file without warning about secret exposure risks such as shell history leakage, process environment disclosure, backups, or overly permissive file permissions. In a cloud asset-management CLI, compromise of these credentials could allow unauthorized access to repositories, assets, imports/exports, and related cloud resources.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Documenting VERIFY_SSL=false as a troubleshooting measure normalizes an unsafe default or unsafe operational mode for a networked cloud CLI. In this skill's context, the danger is elevated because the tool manages cloud assets and uses AK/SK credentials, so users may disable transport validation during sensitive operations and expose themselves to MITM attacks and malicious endpoint impersonation.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 123)May include surrounding context.

md
| `OBS upload failed` | Check `cloudrobo-obs` endpoint configuration and DNS reachability |
| `FileNotFoundError` | `import-asset` requires `local_path` to exist |
| `No versions found` | `export-asset` requires at least one version |
| SSL verification errors | Set `CLOUDROBO_VERIFY_SSL=false` (debug only) |

## Environment Variables 环境变量

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown describes delete-asset and shows a successful cleanup flow, but it does not include any warning that the operation is destructive or may remove user-managed assets. The API summary also lists multiple delete and batch-delete endpoints without any caution about data loss or reversibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown explicitly documents reading from local paths, uploading folders to object storage, downloading content, creating directories, and writing README.md files, but it provides no warning about modifying local files or transferring data to remote storage. For markdown files, the expected disclosure is a warning when behavior can affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L12 specifies the friendly message "该资产版本没有血缘关系", which hardcodes a Chinese response for users regardless of their language preference. This is a language-policy issue because the file does not indicate any user choice or justified region-specific restriction.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
88% confidence
Finding

The documentation explicitly describes disabling SSL verification via CLOUDROBO_VERIFY_SSL=false, which can normalize an insecure practice. If users follow this guidance outside tightly controlled debugging scenarios, they become vulnerable to man-in-the-middle attacks, especially because this skill uses AK/SK-signed requests and may also enable traffic logging that could expose sensitive material.

Content

Scanner excerpt · references/iam-policies.md (reported line 60)May include surrounding context.

md
- **Signing mechanism** — APIG HMAC-SHA256 signs each request with a timestamp to prevent
  replay attacks
- **Proxy support** — Optional HTTP/HTTPS proxy can be configured for network isolation
- **SSL verification** — Can be disabled for debugging (`CLOUDROBO_VERIFY_SSL=false`) but
  should be enabled in production
- **Traffic logging** — `CLOUDROBO_LOG_TRAFFIC=true` enables request/response logging for
  debugging; disable in production to avoid credential leakage in logs

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that users may access an English alternative or choose their preferred language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The verification steps require specific Chinese section headers such as '概述', '前置条件', and others, which effectively enforces a particular language format. The file does not indicate that this locale requirement is optional, user-selected, or justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The test case explicitly uses --language zh in the CLI path and language='zh' in the SDK path, forcing a specific language/locale. This matches the locale policy violation category because the script does not offer an opt-in, fallback, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Lines L047-L048 specify verification commands using --language zh, which imposes a specific language setting in natural-language guidance. The file does not indicate that this is optional, user-selected, or required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The configuration example hard-codes region: cn-southwest-2 without explaining that this is only an example or instructing users to choose an appropriate region. The policy category applies to locale/region constraints that are imposed without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The heading mixes English with Chinese ("边界情况"), which imposes a specific language in the skill content without any visible opt-in or explanation that the skill is intended for a Chinese-speaking audience. Under the policy, locale or language constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The headings and labels are presented bilingually with Chinese prominently embedded throughout the document, but there is no indication that this language choice is optional, user-selectable, or required for a specific regional compliance context. Under the policy rule, forcing a specific language or locale without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The text explicitly limits the language field to zh or en and does not explain why only those locales are permitted. This is a locale policy concern because it constrains language selection without documented justification or broader opt-in framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.