Back to skill

Security audit

huawei-cloud-cloudrobo-workspace

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed CloudRobo workspace management guide with powerful workspace and member operations that require careful user confirmation.

Install only if you want an agent to administer CloudRobo workspaces. Use least-privilege AK/SK credentials, keep TLS verification enabled, confirm exact workspace and user IDs before deletes or role changes, prefer dry-run first, and remember that switching workspaces writes persistent local context used by other CloudRobo skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description says this skill manages CloudRobo workspaces and related member/context operations. However, the provided code chunk is not the implementation of such a management skill; it is a test script designed to exercise and validate CLI/SDK commands for that skill. While the tested commands align with the described workspace domain, the actual code’s primary purpose is automated/manual verification, not direct workspace management. It also includes credential discovery logic and interactive mutation-test orchestration, which are materially different from the declared end-user functionality. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The skill exposes an irreversible delete operation for workspaces, and the document itself notes async cleanup of associated resources. In an agent context, parameterized destructive actions are dangerous because a mistaken, injected, or ambiguous workspace_id could lead to permanent deletion of the wrong workspace and downstream loss of dependent assets or service availability.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

text

- **SDK:** `client.delete_workspace(workspace_id: str)`
- **API:** `DELETE /v1/workspaces/{workspace_id}`

Deletion is irreversible. Only root user or workspace owner can delete. The default
workspace cannot be deleted. Server creates async cleanup tasks on deletion.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill supports bulk deletion of workspace members via user-controlled user_ids. In an agent setting, this can be abused through parameter injection or operator confusion to remove unintended members, causing access disruption, privilege changes, and potential denial of service for legitimate users of the workspace.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

text

- **SDK:** `client.delete_workspace_members(workspace_id: str, user_ids: list)`
- **API:** `DELETE /v1/workspaces/{workspace_id}/members?user_ids=<ids>`

The workspace owner cannot be deleted. The default workspace does not support member
operations. Max 20 user IDs per request (API constraint) / 100 per request (CLI constraint).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 354)May include surrounding context.

md
See `templates/test-vars.json` for the full test case list covering workspace CRUD, member

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 123)May include surrounding context.

md
Agent->>CLI: workspace delete --workspace-id <id>
    CLI->>SDK: delete_workspace(id)
    SDK->>API: DELETE /v1/workspaces/{id}
    API->>API: create cleanup tasks (async)
    API-->>SDK: 204 No Content
    SDK-->>Agent: deleted

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 163)May include surrounding context.

md
Agent->>CLI: workspace delete-members --workspace-id <id> --user-ids <u1,u2>
    CLI->>SDK: delete_workspace_members(id, [u1, u2])
    SDK->>API: DELETE /v1/workspaces/{id}/members?user_ids=u1,u2
    API->>API: validate not owner + not default workspace
    API-->>SDK: 204 No Content
    SDK-->>Agent: deleted

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill persists active workspace context in ~/.cloudrobo/workspace.json for reuse by other skills, creating cross-session and cross-skill state. Even though the file is documented as 0600, persistent local context can cause confused-deputy behavior, unintended targeting of the wrong workspace, or leakage of workspace metadata to later operations if users are not clearly warned and asked to confirm context changes.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
all other skills (dataset, train, eval, infer) read the active workspace from
  `~/.cloudrobo/workspace.json`
- **Overview & quota** — View workspace capacity, used count, available count, member count
- **Onboarding** — First-time setup: create workspace → switch to it → start using other skills

**Architecture:**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

Workspace Management 工作空间管理

Create a workspace

bash
cloudrobo workspace create --name <workspace-name> --default-obs-path <obs://bucket/path> [--description <description>] [--tags <tag1,tag2>] [--member-list '<json>'] [--dry-run]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes the cloudrobo workspace delete operation as a normal verification step, but it does not warn that the action removes a workspace and may affect user data or configuration. For markdown files, the criteria require warnings when behaviors could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes managing CloudRobo workspaces, members, overview, and active workspace context for normal skill usage. This file additionally documents an internal API (/v1/internal/workspaces) intended for service-to-service calls without IAM auth, which is not justified by the stated user-facing purpose and suggests capability beyond the declared workspace-management scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs users to place long-lived AK/SK credentials in shell environment variables and optionally in a plaintext config file under the home directory, but it does not warn about the exposure risks of those storage methods. Secrets in environment variables can leak via shell history, process inspection, crash dumps, CI logs, or inherited subprocess environments, while plaintext config files are vulnerable to local disclosure and backup/sync leakage.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 91)May include surrounding context.

md
| `未配置工作空间` | Run `cloudrobo workspace use --workspace-id <id>` |
| `HTTP 401/403` | Check AK/SK credentials in environment or config |
| `HTTP 404` | Check service endpoint in `~/.cloudrobo/config.yaml` |
| SSL verification errors | Check CA certificates; set `CLOUDROBO_VERIFY_SSL=false` only for local debugging against trusted endpoints |
| `切换失败: ...` | Workspace ID is invalid or not accessible; verify with `workspace list` |

## Environment Variables 环境变量

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 112)May include surrounding context.

md
| `未配置工作空间` | Run `cloudrobo workspace use --workspace-id <id>` |
| `HTTP 401/403` | Check AK/SK credentials in environment or config |
| `HTTP 404` | Check service endpoint in `~/.cloudrobo/config.yaml` |
| SSL verification errors | Check CA certificates; set `CLOUDROBO_VERIFY_SSL=false` only for local debugging against trusted endpoints |
| `切换失败: ...` | Workspace ID is invalid or not accessible; verify with `workspace list` |

## Environment Variables 环境变量

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown documents a workspace delete operation and shows it returns deletion success after issuing a DELETE request, but it does not warn that the action is destructive or that cleanup tasks will be triggered asynchronously. For markdown files, safety-relevant behaviors that can affect user data or system integrity should include a user-facing warning.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
93% confidence
Finding

The document explicitly advertises an option to disable TLS certificate verification via CLOUDROBO_VERIFY_SSL=false. Even though it says this is only for debugging and should be enabled in production, documenting an easy insecure toggle in an auth-sensitive AK/SK-based workflow can normalize unsafe operation and expose users to man-in-the-middle attacks, endpoint spoofing, and credential theft if copied into real environments.

Content

Scanner excerpt · references/iam-policies.md (reported line 94)May include surrounding context.

md
- **Signing mechanism** — APIG HMAC-SHA256 signs each request with a timestamp to prevent
  replay attacks
- **Proxy support** — Optional HTTP/HTTPS proxy can be configured for network isolation
- **SSL verification** — Can be disabled for debugging (`CLOUDROBO_VERIFY_SSL=false`) but
  should be enabled in production
- **Traffic logging** — `CLOUDROBO_LOG_TRAFFIC=true` enables request/response logging for
  debugging; disable in production to avoid credential leakage in logs

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest includes a hard-coded expected string in Chinese ('未配置工作空间') as the accepted output for the current-workspace test. Because the file does not state that the skill is region-specific or that language is configurable, it appears to enforce a specific locale in violation of the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The expected output for switching workspaces is hard-coded in Chinese ('已切换到工作空间: ...'). In the absence of documentation that this skill is limited to a Chinese locale or that users can choose their preferred language, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file instructs testers to run delete-members but provides no warning that this changes workspace access and can remove users' permissions. In markdown documentation, access-affecting or potentially disruptive actions should include user-facing cautionary language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

AC-25 requires the exact output 未配置工作空间, which implies a specific locale expectation, while the file does not state that the skill is Chinese-language-only or that language is configurable. The policy allows locale constraints when they are clearly documented and justified, which is not evident here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation includes workspace delete-members and a DELETE endpoint for removing members, but it provides no warning that this action revokes user access and can impact workspace administration. In markdown descriptions, access-affecting operations should include a clear caution when they modify permissions or membership.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file presents headings and content in a fixed bilingual Chinese/English format, which can impose a language/locale choice on users without explicit opt-in. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy concern unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents that workspace use creates ~/.cloudrobo/workspace.json, which stores workspace identifiers and paths on the local system. Although file permissions are noted, there is no explicit warning that the command writes persistent local context data that may affect subsequent operations or expose workspace metadata on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code enumerates environment variables matching access-key and secret-key patterns and dereferences their values, which is sensitive credential access. Although the script prints that credentials were found, it does not explicitly warn the user beforehand that it will inspect credential-related environment variables.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.