Back to skill

Security audit

huawei-cloud-cloudrobo-infer

Security checks for vulnerabilities and agentic risk

Overview

The skill’s CloudRobo service-management purpose is clear, but an included test script can start, stop, update, and delete a real cloud service without an enforced confirmation prompt.

Review this before installing or running it with real CloudRobo credentials. Use least-privilege AK/SK credentials and a non-production workspace where possible. Do not run scripts/test-cli-commands.sh with SERVICE_ID set unless you are prepared for it to start, stop, update, and delete that service; prefer read-only commands or dry-run flows until the script is changed to require explicit confirmations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/test-cli-commands.sh:69
Finding

Verification Script Performs Destructive Cloud Operations Without Enforced Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/test-cli-commands.sh, lines 69–103
Vulnerability Type: Missing confirmation gate for destructive operations
Risk Level: High

Complete Code Snippet:

bash
SERVICE_ID=${SERVICE_ID:-}
if [ -n "$SERVICE_ID" ]; then
    echo "Test 4: Show service detail"
    cloudrobo infer show --service-id "$SERVICE_ID"
    echo ""

    echo "Test 5: Start service (user must confirm)"
    echo "WARNING: This starts the service, consuming pool resources. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo infer start --service-id "$SERVICE_ID" || echo "Start may fail if already running"
    echo ""

    echo "Test 6: Stop service (user must confirm)"
    echo "WARNING: This stops the service. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo infer stop --service-id "$SERVICE_ID" || echo "Stop may fail if already stopped"
    echo ""

    echo "Test 7: List logs (ms timestamps)"
    END_MS=$(date +%s%3N 2>/dev/null || echo "0")
    START_MS=$(( END_MS - 3600000 ))
    cloudrobo infer list-logs --service-id "$SERVICE_ID" --start-time "$START_MS" --end-time "$END_MS" --limit 50 || echo "Logs may be empty if service never ran"
    echo ""

    echo "Test 8: Update service (user must confirm)"
    echo "WARNING: This updates the service. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo infer update --service-id "$SERVICE_ID" --description "Updated by test" || echo "Update may fail"
    echo ""

    echo "Test 9: Delete service (user must confirm)"
    echo "WARNING: This deletes the service. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo infer delete --service-id "$SERVICE_ID" || echo "Delete may fail if service already gone"
    echo ""
fi

Technical Analysis

The documented verification entry point is:

bash
bash scripts/test-cli-commands.sh

When the process environment contains a nonempty SERVICE_ID, the script automatically starts, stops, updates, and ultimately deletes that inference servi ...[truncated 2245 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make all mutating tests opt-in through an explicit option, such as:

    bash
    bash scripts/test-cli-commands.sh --run-mutating-tests
    

    Keep the default execution path strictly read-only.

  2. Require an affirmative interactive response immediately before each mutation:

    bash
    read -r -p "Start service $SERVICE_ID? Type YES to continue: " answer
    [ "$answer" = "YES" ] || exit 1
    
  3. Require a separate, stronger confirmation for deletion, including the exact service ID:

    bash
    read -r -p "Type the service ID to confirm permanent deletion: " answer
    [ "$answer" = "$SERVICE_ID" ] || exit 1
    
  4. Refuse destructive execution in non-interactive environments unless a narrowly scoped, explicit confirmation mechanism is supplied. Do not treat a generic environment variable as authorization.

  5. Prefer --dry-run for update and delete verification where supported. Separate destructive end-to-end tests from the ordinary smoke-test script.

  6. Validate the service with show and display its workspace, name, and status before requesting confirmation, reducing the risk of acting on the wrong identifier.

  7. Remove the “Press Ctrl+C to cancel” pattern. A short cancellation window is not an acceptable replacement for positive confirmation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
> Read the [Wait-Deploy](references/service-config-catalog.md#wait-deploy-cli-helper) reference for exact semantics.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

md
> Read the [Wait-Deploy](references/service-config-catalog.md#wait-deploy-cli-helper) reference for exact semantics.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
> Read the [Wait-Deploy](references/service-config-catalog.md#wait-deploy-cli-helper) reference for exact semantics.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 403)May include surrounding context.

md
> Read the [Wait-Deploy](references/service-config-catalog.md#wait-deploy-cli-helper) reference for exact semantics.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 407)May include surrounding context.

md
> Read the [Wait-Deploy](references/service-config-catalog.md#wait-deploy-cli-helper) reference for exact semantics.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 55)May include surrounding context.

md
| Create service | Write access to `cloudrobo-service` (`POST /v1/infer-services`) |
| Show service detail | Read access to `cloudrobo-service` (`GET /v1/infer-services/{service_id}`) |
| Update service | Write access to `cloudrobo-service` (`PUT /v1/infer-services/{service_id}`) |
| Delete service | Delete access to `cloudrobo-service` (`DELETE /v1/infer-services/{service_id}`) |
| Start / stop service | Write access to `cloudrobo-service` (`POST /v1/infer-services/{service_id}/start`, `.../stop`) |
| List service logs | Read access to `cloudrobo-service` (`POST /v1/infer-services/{service_id}/logs`) |
| Query model asset (deploy source) | Read access to `cloudrobo-asset-manager` model assets |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/service-config-catalog.md (reported line 168)May include surrounding context.

md
| list_infer_services | `list_infer_services(**params)` | `list` | `GET /v1/infer-services` |
| show_infer_service | `show_infer_service(service_id)` | `show` | `GET /v1/infer-services/{service_id}` |
| update_infer_service | `update_infer_service(service_id, req)` | `update` | `PUT /v1/infer-services/{service_id}` |
| delete_infer_service | `delete_infer_service(service_id)` | `delete` | `DELETE /v1/infer-services/{service_id}` |
| start_infer_service | `start_infer_service(service_id)` | `start` | `POST /v1/infer-services/{service_id}/start` |
| stop_infer_service | `stop_infer_service(service_id)` | `stop` | `POST /v1/infer-services/{service_id}/stop` |
| list_infer_service_logs | `list_infer_service_logs(service_id, req)` | `list-logs` | `POST /v1/infer-services/{service_id}/logs` |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 117)May include surrounding context.

md
{
      "id": "TC-13",
      "name": "path-traversal-rejected",
      "command": "cloudrobo infer show --service-id '../etc/passwd'",
      "description": "Verify path traversal is rejected via validate_safe_id",
      "expected": "Error: validation error",
      "type": "read"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · templates/test-vars.json (reported line 102)May include surrounding context.

json
{
      "id": "TC-13",
      "name": "path-traversal-rejected",
      "command": "cloudrobo infer show --service-id '../etc/passwd'",
      "description": "Verify path traversal is rejected via validate_safe_id",
      "expected": "Error: validation error",
      "type": "read"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases such as 'infer', 'inference', and 'model deployment', which can cause the skill to activate in situations where the user did not clearly intend to manage CloudRobo services. Because this skill performs infrastructure-affecting operations like create, start, stop, update, and delete, accidental invocation can route users into high-impact operational workflows and increase the chance of unintended changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The acceptance criteria explicitly cover mutating lifecycle operations such as start, stop, update, and delete, but the documented verification steps in this file do not include any user-facing warning or confirmation requirement at the point of action. In the context of an infrastructure-management skill for inference services, omission of explicit safeguards increases the risk of unintended service disruption, accidental deletion, or unauthorized state changes being normalized in implementation and testing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide instructs users to place long-lived Huawei Cloud access keys in environment variables without any caution about credential sensitivity, shell history exposure, process/environment leakage, or preference for short-lived credentials. In a CLI used to manage cloud inference services, exposed AK/SK values could allow unauthorized access to cloud resources, service logs, deployments, and other workspace operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The subcommand table documents operations such as cloudrobo infer delete, start, stop, and update, which can affect deployed services and potentially user workloads, but the markdown provides no warning about destructive or service-impacting behavior. For markdown files, omission of warnings about actions that can affect user data or system integrity is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all user-facing headings and explanatory text in Chinese only, which can constitute a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that it is intended exclusively for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 362)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 455)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 63)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/service-config-catalog.md (reported line 100)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/service-config-catalog.md (reported line 223)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 42)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 89)May include surrounding context.

md
cloudrobo infer create --name verify-infer --flavor "<flavor>" --model-json '{"model_id": "<asset-id>", "model_version_id": "<latest-version-id>"}' --workspace-id <ws-id> --pool-id pool-<resource-id> --pool-type <pool-type> --stop-schedule-json '{"duration": 60, "time_unit": "MINUTES"}'
# → Returns service_id (service auto-enters CREATING → DEPLOYING)

# 7. Wait for deployment (do NOT call start — service auto-deploys)
cloudrobo infer wait-deploy --service-id <service-id> --timeout 600
# → Polls every 5s until status is no longer DEPLOYING (status != DEPLOYING)
#   (returns RUNNING/FAILED/...; if it returns while CREATING, re-invoke — it only waits on DEPLOYING)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The trigger list explicitly embeds both English and Chinese trigger phrases, effectively steering activation behavior around specific languages without stating that the user may choose language or that the skill is region-specific. That creates a locale-policy concern because the file defines language-specific activation behavior but does not document user choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.