Back to skill

Security audit

huawei-cloud-cloudrobo-dataset

Security checks for vulnerabilities and agentic risk

Overview

Review before installing: the skill is coherent for CloudRobo task management, but it handles cloud credentials and destructive task operations while documenting insecure SSL and credential-handling practices.

Install only if you intend to let the agent operate CloudRobo tasks in your workspace. Use least-privilege AK/SK credentials, prefer environment variables over plaintext config files, keep SSL verification enabled, avoid traffic logging with secrets, and require explicit confirmation before create, restart, update, or delete actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description claims an operational skill that manages CloudRobo processing/evaluation tasks and provides broad lifecycle, orchestration, polling, download, and diagnostic capabilities. The supplied code chunk is instead a test harness that invokes selected CLI/SDK commands to verify behavior. Its main function is automated testing, not performing those management workflows for a user. While some described areas are partially touched (listing tasks, showing tasks, listing algorithms, fetching logs/previews), many core declared capabilities are absent, and the script includes an undeclared credential-scanning behavior. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
#### Delete tasks (SDK only)

- **SDK:** `client.delete_tasks([task_id_1, task_id_2])`
- **API:** `DELETE /v1/data-eng/proc-tasks?ids=id1,id2`

#### Restart a task

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
#### Delete an evaluation task (single granularity, SDK only)

- **SDK:** `client.delete_eval_task(task_id)`
- **API:** `DELETE /v1/data-eng/eval-tasks/{task_id}`

**Note:** eval-tasks deletion is single-task granularity (`delete-task`), same as proc-tasks
(`delete-task`). eval-tasks do not support restart.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 444)May include surrounding context.

md
See `templates/test-vars.json` for the full test case list covering proc-tasks, eval-tasks,

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting advice tells users to disable SSL verification for debugging without a prominent warning about interception risks. Because this CLI uses cloud authentication and transfers operational data and logs, disabling certificate validation can allow man-in-the-middle attacks that capture credentials or tamper with responses.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 102)May include surrounding context.

md
Agent->>CLI: delete-task
    CLI->>SDK: delete_tasks([task_id])
    SDK->>API: DELETE /v1/data-eng/proc-tasks?ids=...
    API-->>SDK: deleted
    SDK-->>CLI: success
    CLI-->>Agent: cleanup done

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes very broad keywords such as 'dataset' and generic task-management phrases, which can cause the skill to activate in unrelated contexts. In a skill with destructive capabilities like create/update/delete/restart operations and log access, unintended invocation increases the chance of accidental data exposure or unintended state-changing actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L325-L328 define evaluation-task deletion as single-task granularity, but L330-L331 says this is 'same as proc-tasks (delete-task)'. Earlier, L185-L188 document proc-task deletion as batch deletion via multiple IDs, so the note actively misstates the behavior and could mislead operators about destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to place AK/SK secrets directly into ~/.cloudrobo/config.yaml without warning that this is a plaintext secret store. On multi-user systems, in backups, or via accidental file disclosure, these credentials could be exposed and reused to access Huawei Cloud resources.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

The documented VERIFY_SSL=false guidance reflects an unsafe default or at minimum an endorsed insecure mode in a security-sensitive CLI. In the context of dataset, processing, evaluation, and log-management workflows backed by cloud APIs, this weakens transport security for both credentials and potentially sensitive task data.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 106)May include surrounding context.

md
| `缺少 workspace_id 参数` | Run `cloudrobo workspace use --workspace-id <id>` |
| `HTTP 401/403` | Check AK/SK credentials in environment or config |
| `HTTP 404` | Check service endpoint in `~/.cloudrobo/config.yaml` |
| SSL verification errors | Set `CLOUDROBO_VERIFY_SSL=false` (debug only) |

## Environment Variables 环境变量

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The architecture diagram explicitly references sensitive environment variables HUAWEI_CLOUD_AK/SK flowing into configuration, but the file provides no warning about credential sensitivity, secure storage, or avoiding accidental exposure. Under SQP-2 for markdown, descriptions that involve credentials should warn about privacy and system-impact risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This documentation shows an agent invoking delete-task and receiving cleanup done, and later summarizes DELETE endpoints for task deletion, but it does not warn that deleting tasks may remove user resources, logs, or outputs. For markdown files, SQP-2 applies when skill descriptions omit warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/iam-policies.md (reported line 60)May include surrounding context.

md
- **Signing mechanism** — APIG HMAC-SHA256 signs each request with a timestamp to prevent
  replay attacks
- **Proxy support** — Optional HTTP/HTTPS proxy can be configured for network isolation
- **SSL verification** — Can be disabled for debugging (`CLOUDROBO_VERIFY_SSL=false`) but
  should be enabled in production
- **Traffic logging** — `CLOUDROBO_LOG_TRAFFIC=true` enables request/response logging for
  debugging; disable in production to avoid credential leakage in logs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow directs the agent to display a summary, ask for confirmation, and then submit the processing task in the same turn. In an interactive agent setting, combining confirmation collection with immediate resource-creating execution reduces user control and can lead to accidental job creation, dataset processing, workspace modification, and billable compute/storage consumption without a distinct pause for review. Because this skill manages real CloudRobo processing tasks and resource pools, the operational context makes the issue more dangerous than a purely read-only workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The evaluation-task flow omits an explicit warning that confirming will create a task that can process datasets and consume shared or dedicated resources. This creates a consent and safety gap: users may treat the confirmation as informational rather than authorization for a state-changing, potentially costly action. In this skill's context, eval tasks can trigger compute usage and data processing, so the missing warning materially increases the chance of unintended execution.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/task-config-catalog.md (reported line 55)May include surrounding context.

md
## Optional Fields

| Field                 | Description                                                                                             |
|-----------------------|---------------------------------------------------------------------------------------------------------|
| `algo_path`           | Algorithm path (required when `algo_type=OBS_ASSETS`, OBS storage path for algorithm code/files)        |
| `job_local_path`      | Container mount path (required when `algo_type=OBS_ASSETS`, mount path for algorithm data in container) |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/task-config-catalog.md (reported line 64)May include surrounding context.

md
## algo_type Values

| Algorithm Source          | algo_type Value    | Required Fields                                                                                                 |
|---------------------------|--------------------|-----------------------------------------------------------------------------------------------------------------|
| Preset algorithm          | `PRESET_ASSETS`    | `algo_id`, `algo_name`, `algo_entrance`, `image` (extract from operator ext_metadata)                           |
| Workspace asset algorithm | `WORKSPACE_ASSETS` | `algo_id`, `algo_name`, `algo_entrance`, `image` (extract from workspace operator ext_metadata)                 |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown repeatedly requires bilingual Chinese structure and headers, such as the title and the required section checks for Chinese header terms. This is a natural-language locale constraint, but the file does not present it as optional user preference or justify it as a region-specific requirement.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 97)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 99)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/verification-method.md (reported line 19)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/verification-method.md (reported line 22)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/verification-method.md (reported line 25)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/verification-method.md (reported line 28)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/verification-method.md (reported line 35)May include surrounding context.

bash
# Check frontmatter exists
grep '^---$' skills/cloudrobo-dataset/SKILL.md | head -2

# Check name field
grep '^name:' skills/cloudrobo-dataset/SKILL.md

Static analysis

No suspicious patterns detected.