Back to skill

Security audit

huawei-cloud-codearts-pipeline-diagnose

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Huawei CodeArts functions are coherent, but it requires an extra telemetry wrapper that can be downloaded, installed persistently, and used for every cloud command without enough integrity or privacy detail.

Install only if you are comfortable with a separate telemetry CLI being installed into your user bin directory and wrapping every Huawei Cloud command. Prefer read-only Huawei Cloud credentials unless you need create/start/delete actions, disable telemetry with SKILL_QUALITY_REPORT=0 for sensitive environments, and review or preinstall the quality CLI from a trusted source before allowing the installer scripts to run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Requiring installation of a separate CLI, downloading artifacts from unrelated endpoints, and writing executables into the user's local bin directory materially expands the skill's behavior beyond infrastructure diagnosis. This creates unnecessary supply-chain risk and persistence on the host, especially because the extra software-installation behavior is not the user's primary expected outcome.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Requiring installation of a separate CLI, downloading artifacts from unrelated endpoints, and writing executables into the user's local bin directory materially expands the skill's behavior beyond infrastructure diagnosis. This creates unnecessary supply-chain risk and persistence on the host, especially because the extra software-installation behavior is not the user's primary expected outcome.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
listed in `references/iam-policies.md` for create/start/delete

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 488)May include surrounding context.

md
listed in `references/iam-policies.md` for create/start/delete

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The script retrieves version metadata from a remote API and then downloads and installs a binary tarball based on that response, but it performs no signature or checksum verification before extraction and execution-ready placement. This is a classic supply-chain risk: if the API, storage endpoint, DNS, TLS trust chain, or publishing pipeline is compromised, an attacker can deliver malicious code that becomes persistently installed in the user's environment.

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 16)May include surrounding context.

sh
API_URL="https://skillsapi.developer.myhuaweicloud.com/api/quality/cli/latest"
OBS_BASE="https://obs-skills-repository.obs.cn-north-4.myhuaweicloud.com/skill-quality-cli"

V=$(curl -s "${API_URL}" | python3 -c 'import sys,json;print(json.load(sys.stdin)["version"])' 2>/dev/null)
if [ -z "$V" ]; then
    echo "警告: 无法获取 skill-quality-cli 最新版本,跳过安装" >&2
    exit 0

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

The script fetches remote data to determine a version and then downloads and installs a corresponding archive, but it performs no signature or checksum verification on either response. This creates a supply-chain risk: if the API, storage bucket, DNS, TLS trust, or publishing pipeline is compromised, an attacker can cause arbitrary code to be installed on the user's machine.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 12)May include surrounding context.

sh
API_URL="https://skillsapi.developer.myhuaweicloud.com/api/quality/cli/latest"
OBS_BASE="https://obs-skills-repository.obs.cn-north-4.myhuaweicloud.com/skill-quality-cli"

V=$(curl -s "${API_URL}" | python3 -c 'import sys,json;print(json.load(sys.stdin)["version"])' 2>/dev/null)
if [ -z "$V" ]; then
    echo "无法获取 skill-quality-cli 最新版本" >&2
    exit 1

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill prescribes shell command execution but declares no explicit tool scope such as permissions or allowed-tools. In practice this weakens platform-side guardrails, making it easier for the skill to invoke unexpected shell behavior or ancillary tooling without clear authorization boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest trigger list includes generic terms such as "pipeline", "构建", "CI/CD", and "持续集成", which are broad phrases that can appear in many unrelated conversations about software delivery. The file does not provide exclusion conditions or negative examples in the trigger definition to limit unintended activation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates a telemetry wrapper for every command and states that quality data is auto-collected beyond the core operational purpose. This can expose command metadata, project identifiers, and operational patterns to an additional component or service, increasing privacy and data-handling risk without clear necessity for the requested task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to use the skill for CodeArts operations or CI/CD troubleshooting is broad, and the listed trigger phrases again include generic terms like "pipeline", "build log", and "CI/CD". Although user examples are provided, there are no explicit non-matching examples or boundaries distinguishing Huawei CodeArts requests from general build/pipeline discussions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide states that telemetry is enabled automatically and only mentions an opt-out flag, but it does not disclose what information is collected, when it is transmitted, or any privacy/security implications. In an operational DevOps context, telemetry could include project metadata, command usage, environment details, or failure information, creating a real risk of unreviewed data exfiltration from build and pipeline environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This bootstrap script installs and persists an unrelated 'skill-quality-cli' component even though the skill is described as CodeArts pipeline/build management. Introducing an unnecessary secondary tool expands the trust boundary and creates an undocumented supply-chain dependency that can execute in the user's environment, which is especially risky because the install happens automatically and failures are intentionally non-blocking/quiet.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The script copies executables and Python entry files into ~/.local/bin and a persistent directory under the user's home, leaving tooling installed beyond the current run. That persistence can be abused for long-lived execution or future unintended invocation, and it is more dangerous here because the installed tool is not obviously related to the advertised CodeArts functionality.

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 35)May include surrounding context.

sh
tar xzf "${TMPDIR}/sqc.tar.gz" -C "${TMPDIR}"

mkdir -p ~/.local/bin/skill-quality-cli.d
cp "${TMPDIR}/skill-quality-cli" ~/.local/bin/ 2>/dev/null
cp "${TMPDIR}/skill-quality-cli.bin" ~/.local/bin/ 2>/dev/null
cp "${TMPDIR}/skill-quality-cli.d/cli_entry.py" ~/.local/bin/skill-quality-cli.d/ 2>/dev/null

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This skill includes an installer for a separate 'skill-quality-cli' utility that is not part of the stated CodeArts pipeline/build diagnosis functionality. Bundling and installing extra tooling expands the attack surface and can introduce opaque capabilities or supply-chain risk, especially because the binary is fetched remotely and persisted into the user's local PATH area.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The script copies downloaded executables and Python entry files into ~/.local/bin and ~/.local/bin/skill-quality-cli.d, making the fetched tooling persist across future sessions. Because these artifacts are obtained from the network without integrity verification, persistence increases the blast radius of a compromised download or repository and can leave long-lived unreviewed code on the host.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 25)May include surrounding context.

sh
curl -fsSL -o "${TMPDIR}/sqc.tar.gz" "${OBS_BASE}/v${V}/skill-quality-cli-v${V}-linux-${ARCH}.tar.gz"
tar xzf "${TMPDIR}/sqc.tar.gz" -C "${TMPDIR}"

mkdir -p ~/.local/bin/skill-quality-cli.d
cp "${TMPDIR}/skill-quality-cli" ~/.local/bin/ 2>/dev/null
cp "${TMPDIR}/skill-quality-cli.bin" ~/.local/bin/ 2>/dev/null
cp "${TMPDIR}/skill-quality-cli.d/cli_entry.py" ~/.local/bin/skill-quality-cli.d/ 2>/dev/null

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest sets the default region to "cn-north-4", which imposes a specific geographic/locale context on all listed test commands. Under the policy, locale constraints should be user-selectable or explicitly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The JSON sets "region" to "cn-north-4", which imposes a specific regional/locale setting in natural-language/config behavior. Under the policy rules, forcing a locale or region without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation presents the skill as using hcloud directly, but the actual required execution path is through a different wrapper tool. This inconsistency can mislead reviewers and users about the real trust boundary and may cause them to underestimate the additional code path and data exposure involved.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Earlier guidance says every hcloud command is strictly required to be wrapped with skill-quality-cli run, making bare hcloud calls forbidden. But the later 'KooCLI Command Format Standard' describes the generic invocation shape as direct hcloud <service> <Operation>, which contradicts the earlier mandatory execution rule rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script contains natural-language comments and status messaging in Chinese, including the completion message, with no indication that language selection is configurable or intentionally limited to a Chinese-only audience. Under the policy for natural-language violations, forcing a specific language without user opt-in is in scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.