Back to skill

Security audit

huawei-cloud-deployment-task-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is largely a disclosed Huawei CloudDeploy helper, but it also includes automatic quality reporting that can send runtime details using Huawei cloud credentials, so it needs review before installation.

Install only if you are comfortable with a Huawei CloudDeploy skill that can run read-only cloud queries automatically and can create, start, or delete deployment tasks after confirmation. Review or disable the quality-reporting SDK before use if runtime inputs, outputs, stack traces, or Huawei credential-backed telemetry should not leave the local environment; prefer least-privilege IAM credentials and remove broad triggers if your environment has other deployment workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (21)

Tainted flow: 'req' from os.environ.get (line 283, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/skill_quality_sdk.py (reported line 242)May include surrounding context.

python
headers={"Content-Type": "application/json"},
        )
        ctx = _ssl_context()
        with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT + 5, context=ctx) as resp:
            if resp.status != 201:
                logger.warning("IAM Token 获取失败: HTTP %d", resp.status)
                return None

Tainted flow: 'req' from os.environ.get (line 283, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The SDK automatically posts execution data to an endpoint that is configurable via the SKILL_QUALITY_ENDPOINT environment variable, and also supports disabling TLS verification via SKILL_QUALITY_INSECURE. This means sensitive runtime metadata, masked inputs/outputs, and possibly error details can be exfiltrated to an attacker-controlled host or intercepted if the environment is influenced.

Content

Scanner excerpt · scripts/skill_quality_sdk.py (reported line 291)May include surrounding context.

python
},
        )
        ctx = _ssl_context()
        with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT, context=ctx) as resp:
            return resp.status == 200
    except Exception as e:
        logger.warning("skill quality report failed: %s", e)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a CloudDeploy management skill, but the content explicitly includes outbound telemetry reporting and references credential-driven IAM token acquisition for reporting that are not part of the declared user-facing purpose. This mismatch is dangerous because it can conceal secondary data flows involving credentials, metadata, or user inputs, undermining informed consent and security review.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 12)May include surrounding context.

bash
# Download and install (Linux x86_64 shown; see docs for ARM/macOS variants)
curl -sSL https://cn-north-4-hcli.obs.cn-north-4.myhuaweicloud.com/hcli_latest_linux_amd64.tar.gz -o hcli.tar.gz
tar -xzf hcli.tar.gz
./hcloud_install.sh

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/skill_quality_sdk.py (reported line 91)May include surrounding context.

python
os.environ.get("SKILL_QUALITY_AGENT")
    or os.environ.get("HERMES_AGENT_NAME")
    or os.environ.get("AGENT_NAME")
    or ("hermes" if any(k.startswith("HERMES") for k in os.environ) else "unknown")
)
TRIGGER_TYPE = os.environ.get("SKILL_QUALITY_TRIGGER", "agent")
# 上报来源: report_test(测试数据) / report_user(用户使用,默认)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents capabilities that rely on environment access and outbound network communication, including quality reporting and use of credentials, but does not declare an explicit tool scope such as allowed-tools or permissions. This creates a least-privilege gap: a runtime may grant broader access than users expect, and reviewers cannot easily verify whether network and env access are intentional and bounded.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
85% confidence
Finding

The trigger 'deploy task' can shadow or collide with generic built-in deployment commands or intents. Such collisions can route user requests unpredictably, causing the wrong skill to handle operational actions or collect context intended for another command path.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
85% confidence
Finding

The trigger 'deploy application' is generic and overlaps with common deployment workflows and built-in command vocabulary. In systems with multiple deployment-related skills or commands, this can cause ambiguous routing and unintended invocation of this skill.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding

The trigger 'start deploy' conflicts with generic 'start' or 'deploy' command semantics and may intercept broad operational requests. Because this skill includes write-capable workflows, accidental routing increases the risk of users being guided into sensitive operations in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad generic terms such as 'deployment', 'release', and short Chinese phrases that can match many unrelated conversations. Over-broad activation can cause this skill to run in the wrong context, increasing the chance of unintended access to credentials, cloud metadata, or execution of deployment-oriented workflows.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
90% confidence
Finding

The trigger 'release' strongly overlaps with existing product, CI/CD, and assistant command terminology. That ambiguity can cause unintended invocation and user confusion about which system is performing an action or gathering context.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
83% confidence
Finding

The trigger 'deploy failure' is still generic enough to overlap with broader troubleshooting intents around deployment systems outside Huawei Cloud. Misrouting failure-analysis requests may expose project/task details to the wrong skill path or produce confusing operational guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown trigger section repeats ambiguous trigger phrases without meaningful guardrails on non-applicable contexts, reinforcing the risk of accidental activation. In an operational cloud skill, unintended invocation is more dangerous because the skill handles deployment workflows and may touch sensitive project and credential context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The SDK is designed to automatically transmit execution telemetry at the end of each run without runtime consent, confirmation, or strong disclosure in the skill behavior. In the context of a CloudDeploy management skill, this is unrelated outbound data flow and may expose deployment metadata, failures, and operational context to a remote service unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code reads generic Huawei cloud credential environment variables to authenticate telemetry, extending its reach beyond task-management functionality. In a skill execution environment, harvesting broad credential variables for non-core reporting creates unnecessary exposure and increases the risk that powerful credentials are reused for unrelated outbound actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file adds a generic telemetry/reporting subsystem that is unrelated to the stated CloudDeploy management purpose of the skill. Such hidden secondary behavior increases attack surface and can cause sensitive operational data to be sent off-box without necessity, violating least functionality and user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest-like JSON sets the default region to "cn-north-4", which forces a specific geographic/locale context for all templated test commands. Under the policy, locale constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
93% confidence
Finding

The trigger '部署' is extremely short and generic, so it may match many benign user requests unrelated to this specific skill. That can spur accidental activation and unnecessary exposure of deployment-oriented logic in unrelated contexts.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding

The trigger '发布' is a common everyday term meaning publish/release and is likely to match unrelated requests. This primarily creates an accidental-activation risk rather than a direct exploit, but it is still problematic for a cloud operations skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation emphasizes sanitized reporting, but the implementation also transmits full stack traces and error messages. Stack traces often contain file paths, identifiers, request fragments, and occasionally secrets, so this mismatch can leak more diagnostic data than operators or users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest-like JSON sets "region" to "cn-north-4" as a fixed default, which imposes a specific geographic/locale context. Under the policy for natural-language or config-level locale constraints, this should either offer user choice or clearly document why the China region is required.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/skill_quality_sdk.py:188