Back to skill

Security audit

huawei-cloud-computing-query

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a Huawei Cloud query tool, but it includes unsafe setup behavior and can expose server passwords or console access details without adequate safeguards.

Review carefully before installing. Use only least-privilege Huawei Cloud credentials, avoid running the setup on untrusted networks, and do not invoke password or console URL scripts unless you explicitly intend to expose privileged access material. The TLS verification behavior and remote installer fallback should be fixed before routine use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/ensure_env.py:278
Finding

Remote Python Installer Downloaded and Executed Without TLS Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py, lines 28 and 278–294
Vulnerability Type: Unauthenticated remote payload retrieval and execution
Risk Level: High

Vulnerable Code

python
ssl._create_default_https_context = ssl._create_unverified_context
python
get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py")
urls = [
    "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py",
    "https://bootstrap.pypa.io/get-pip.py",
]

ctx = ssl._create_unverified_context()

for url in urls:
    info(f"尝试下载 get-pip.py: {url}")
    try:
        urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    except Exception as e:
        print(f"    下载失败: {e}")
        continue

    rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)

Technical Analysis

The environment bootstrap explicitly replaces Python's default HTTPS context with an unverified context. If pip is unavailable and ensurepip also fails, the script downloads get-pip.py through that unverified TLS connection and immediately executes it with the current Python interpreter.

No certificate validation, pinned hash, or digital-signature verification is performed before execution. HTTPS therefore provides no reliable server authentication on this path. The downloaded file is mutable remote code whose content is not constrained by the audited package.

This path is reachable through the Skill's mandatory environment preparation workflow described in SKILL.md. It is not merely an unused helper, although exploitation specifically requires the local environment to lack a working pip and for ensurepip to fail.

Attack Path

  1. A user invokes the Skill and follows its mandatory environment-check workflow.
  2. scripts/check_env.sh or scripts/check_env.ps1 launches scripts/ensure_env.py.
  3. The environment lacks a usable pip, and the attempted ensurepip --upgrade operation fails.
  4. _ensure_pip() downlo ...[truncated 1251 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the global override:
    python
    ssl._create_default_https_context = ssl._create_unverified_context
    
  2. Do not create or pass ssl._create_unverified_context() to urlretrieve.
  3. Use the platform's validated default TLS context:
    python
    ctx = ssl.create_default_context()
    
  4. Verify the downloaded installer against a securely pinned SHA-256 digest or trusted digital signature before execution.
  5. Download to a securely created temporary file rather than a fixed get-pip.py pathname in the shared temporary directory.
  6. Prefer terminating with manual installation instructions when ensurepip is unavailable instead of automatically executing remotely fetched bootstrap code.
  7. Keep trusted hashes versioned in the Skill package and update them only through a reviewed release process.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config.py:45
Finding

TLS Certificate Verification Disabled for Authenticated Huawei Cloud API Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py, lines 8–9 and 45–65
Vulnerability Type: Improper certificate validation for authenticated API traffic
Risk Level: High

Vulnerable Code

python
# Suppress InsecureRequestWarning caused by ignore_ssl_verification
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
python
def build_http_config():
    """Build HTTP configuration with environment-variable proxy support."""
    http_config = HttpConfig.get_default_config()
    http_config.ignore_ssl_verification = True
    http_config.timeout = (30, 60)
    http_config.retry_times = 3

    proxy_url = _get_proxy_url()
    if proxy_url:
        parsed = urlparse(proxy_url)
        http_config.proxy_protocol = parsed.scheme or "http"
        http_config.proxy_host = parsed.hostname or ""
        http_config.proxy_port = parsed.port or 8080
        http_config.proxy_user = parsed.username or ""
        http_config.proxy_password = parsed.password or ""

    return http_config

Representative sensitive response handling in scripts/ecs/show_server_password.py, lines 43–53:

python
request = ShowServerPasswordRequest()
request.server_id = args.server_id
response = client.show_server_password(request)
password = response.password

if not password:
    print(f"没有找到 ECS 服务器密码 (区域: {Region}, 服务器 ID: {args.server_id})")
    exit(0)

print(password)

Technical Analysis

Every query script that calls build_http_config() receives an SDK configuration with server-certificate validation disabled. The code also suppresses the warning that would ordinarily disclose this insecure state.

Huawei Cloud credentials are used by the SDK to authenticate requests sent under this configuration. Without certificate validation, the client cannot establish that it is communicating with the intended Huawei Cloud endpoint. A network-positioned attacker or an untrusted TLS-intercepting proxy can present an arbitrary certificate ...[truncated 1986 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove:
    python
    http_config.ignore_ssl_verification = True
    
    and retain the SDK's secure certificate-validation default.
  2. Remove global suppression of InsecureRequestWarning; security warnings should remain visible if an insecure configuration is introduced.
  3. If an enterprise TLS-inspection proxy is required, support an explicit CA-bundle path and validate certificates against that trusted CA rather than disabling verification.
  4. Validate proxy configuration, restrict accepted schemes as appropriate, and document that only administrator-approved proxies should be used.
  5. Add automated tests asserting that certificate verification remains enabled for IAM, ECS, BMS, IMS, and Auto Scaling clients.
  6. Rotate affected cloud credentials and server passwords if the Skill has previously run across an untrusted network or proxy.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (71)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does not perform any write operations and remains within Huawei Cloud ECS read/query behavior, so it is aligned at a high level with 'query cloud resources.' However, the declared description is specific about the resources covered and lists many ECS/BMS/IMS/AS query domains, but it does not mention ECS launch templates or launch template versions at all. This script’s primary purpose is specifically to query ECS launch template versions, requiring a launch_template_id and returning version metadata. That is a materially different resource focus than the declared coverage, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云资源查询 - 环境检查前置脚本 (Windows PowerShell)
#>

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata presents this as a query-only cloud inventory tool, but this script retrieves a decrypted/usable ECS server password and prints it directly to stdout. That creates a secret disclosure capability far beyond ordinary resource querying and can expose privileged credentials through agent responses, logs, terminals, or downstream tooling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code calls the API to obtain a server password and then prints the secret value directly, enabling immediate credential exfiltration to any caller that can invoke the script. In the context of a cloud query skill, this is unjustified sensitive-data access and could enable unauthorized login, lateral movement, or persistence on the target server.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Printing a recovered server password without any warning, masking, or confirmation materially increases the chance of accidental exposure in console history, CI logs, transcripts, and agent output. Because credentials are highly sensitive, the lack of friction or safeguards makes misuse and unintended disclosure much more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code globally disables HTTPS certificate verification by replacing the default SSL context with an unverified one. This exposes all subsequent HTTPS downloads and likely SDK/API traffic in the process to man-in-the-middle interception, allowing tampering with downloaded bootstrap code or observation/manipulation of cloud-related requests.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 69)May include surrounding context.

python
# 用 venv Python 重新执行当前脚本
    print(f"  使用虚拟环境 Python: {venv_python}")
    os.execv(venv_python, [venv_python] + sys.argv)

def info(msg):
    print(f"  {msg}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script invokes system package managers and uses sudo-capable installation flows for a skill whose stated purpose is read-only cloud queries. If run in a privileged context, this can modify the host, install arbitrary packages from external repositories, and create a strong supply-chain and host-compromise risk disproportionate to the skill's function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs execution of local shell and Python commands, environment inspection, dependency installation, and network-backed SDK/API queries, yet it declares no explicit tool/permission scope. That creates an over-privileged, ambiguous execution surface where an agent may invoke shell, read environment variables, write files such as a virtualenv/cache, and access the network without policy constraints, increasing the blast radius if the skill package or referenced scripts are compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide documents a capability to retrieve ECS server passwords, which is sensitive credential material and exceeds the skill metadata's stated no-write, query-oriented resource-browsing scope. Even though it is a read API, exposing or normalizing password retrieval in a general query skill can directly enable credential disclosure and subsequent host compromise if the caller is not tightly authorized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide presents server password retrieval with no warning about secret-handling, output exposure, or downstream compromise risk. This omission increases the chance that operators or integrating agents will print, store, or transmit credentials insecurely, turning a sensitive capability into an easy disclosure vector.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation advertises retrieval of VNC remote console login addresses, which expands the skill from passive inventory lookup into access-enablement for interactive administration. In the context of a cloud-compute query skill, surfacing console endpoints can facilitate unauthorized access attempts or privileged lateral movement, especially if combined with other leaked credentials or session material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes retrieval of remote console access information without explaining that it can enable privileged interactive access. In a skill positioned as a query/browsing tool, that lack of warning can cause users or downstream systems to underestimate the sensitivity of the returned data and mishandle it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide includes retrieval of serial console login addresses, which similarly goes beyond ordinary resource-query behavior and exposes a highly sensitive administrative access path. Serial console access is particularly risky because it may permit low-level recovery or administration even when network controls differ, increasing the impact of misuse in an otherwise read-oriented skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide omits any warning that serial console access details are security-sensitive and may provide powerful administrative or recovery access. Without that context, consumers may treat the output as ordinary metadata rather than a privileged access path, increasing the chance of accidental exposure or misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes BMS support as querying bare metal servers, flavors, and quotas, but this script queries asynchronous job information by job_id via show_job_infos. Job inspection is a broader operational/status capability that is not mentioned in the declared BMS scope, so the code implements a capability users would not reasonably infer from the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This script retrieves and prints a BMS remote console URL, which is effectively an access artifact for privileged interactive server access rather than ordinary inventory metadata. In a 'query-only' skill, exposing a console login URL materially expands the capability surface and can enable unauthorized or less-audited access if the output is logged, shared, or shown to the wrong user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script prints the remote console URL directly to stdout without any warning, masking, or handling as sensitive data. If terminal output is captured by orchestration logs, chat transcripts, or shared tooling, this can leak a live privileged access path to bare metal servers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script retrieves a Windows bare metal server password and prints it directly to stdout, which can expose highly sensitive credentials through terminal history, CI/CD logs, shell capture, agent transcripts, or other logging/monitoring systems. In the context of an agent skill, this is more dangerous because tool output is often automatically surfaced to users, persisted in conversation history, or stored in observability pipelines, increasing the chance of credential leakage and subsequent host compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This PowerShell script presents its title, status messages, and failure guidance entirely in Chinese, which imposes a specific language on users. The file does not offer any user opt-in, language selection, or documentation that the skill is intentionally limited to a Chinese-only audience or region-specific compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all visible output and comments are written only in Chinese, with no option for the user to select another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 40)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ensure_env.py:284