Back to skill

Security audit

huawei-cloud-cloudrobo-resource

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only CloudRobo resource-query guide, but its handling of cloud credentials is weakened by unsafe SSL-verification guidance.

Install only if you are comfortable using Huawei Cloud AK/SK credentials with this CLI. Keep SSL verification enabled, do not use CLOUDROBO_VERIFY_SSL=false except in tightly controlled debugging, prefer least-privilege credentials, and avoid storing long-lived secrets in plaintext config files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting section recommends setting SSL verification to false without clearly emphasizing that this disables certificate validation and exposes users to man-in-the-middle attacks. Because this CLI handles cloud credentials and API traffic, disabling TLS verification can allow interception of AK/SK secrets, API responses, or endpoint redirection to attacker-controlled services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The acceptance criteria explicitly require bilingual section headers, and the document itself is presented in Chinese and English. Under the policy, forcing a specific language or locale without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to place long-lived AK/SK credentials in environment variables or a local YAML config file, but does not warn that these are highly sensitive secrets or that storing them in plaintext increases the risk of theft through shell history, process inspection, backups, misconfigured file permissions, or accidental commits. In a CLI for cloud resource management, compromised AK/SK credentials could allow unauthorized access to quota and resource-pool APIs and potentially broader cloud actions depending on IAM scope.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

The documentation shows CLOUDROBO_VERIFY_SSL=false as a troubleshooting action, reinforcing an unsafe TLS default/operational pattern. In the context of a cloud-management CLI that may transmit access keys and resource metadata, normalizing disabled certificate validation materially weakens transport security and can lead to credential compromise or tampered API interactions.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 102)May include surrounding context.

md
| `HTTP 401/403` | Check AK/SK credentials in environment or config |
| `HTTP 403 ABAC` | Quota list and pool list require ABAC permission; check IAM policies |
| `HTTP 404` | Pool ID not found; verify with `list-pools` first |
| SSL verification errors | Set `CLOUDROBO_VERIFY_SSL=false` (debug only) |

## Environment Variables 环境变量

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/iam-policies.md (reported line 86)May include surrounding context.

md
- **Signing mechanism** — APIG HMAC-SHA256 signs each request with a timestamp to prevent
  replay attacks
- **Proxy support** — Optional HTTP/HTTPS proxy can be configured for network isolation
- **SSL verification** — Can be disabled for debugging (`CLOUDROBO_VERIFY_SSL=false`) but
  should be enabled in production
- **Traffic logging** — `CLOUDROBO_LOG_TRAFFIC=true` enables request/response logging for
  debugging; disable in production to avoid credential leakage in logs

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The verification steps require specific bilingual/Chinese section header matches such as 概述, 前置条件, and 工作流, which effectively enforces a language/locale convention. This is a natural-language policy concern because the file does not indicate that this locale requirement is optional, user-selected, or justified as region-specific.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/test-cli-commands.sh (reported line 47)May include surrounding context.

sh
echo "Credentials found: AK=${ak:0:8}..."
}

# Read-only test cases (auto-executed)
test_list_quotas() {
    echo "=== TC-01: list-quotas ==="
    if [ "$EXECUTOR" = "cli" ]; then

Static analysis

No suspicious patterns detected.