Back to skill

Security audit

huawei-cloud-devbridge-tunnel

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its DevBridge tunneling purpose, but it needs Review because it can silently install software, authenticate, expose local services anonymously, run background hosts, and delete workspace tunnels without confirmation.

Install only if you are comfortable with a skill that can install a cloud CLI, use Huawei Cloud credentials, and expose local services over a public relay. Before using it, require explicit approval for installer execution, authentication, tunnel creation, anonymous access, selected local port, any file-serving directory, background host processes, and delete-all operations; prefer authenticated access and never tunnel directories or services that may contain credentials or private project files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:203
Finding

Automatic Anonymous Exposure of the Current Working Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:119-141, 203-209, 359-382
Vulnerability Type: Unauthenticated remote file exposure
Risk Level: High

Vulnerable Code

markdown
> **CRITICAL — Zero confirmation during tunnel creation.** Execute the entire flow
> (check CLI → load adaptation layer → check auth → create tunnel → configure port
> → start hosting) fully automatically with ZERO user interaction.

| Anonymous access | Allowed (`--anon allow`) |
bash
db_port_create <tunnelId> -p <port> --protocol <protocol> --anon allow
bash
nohup python3 -m http.server <port> > /tmp/devbridge-service.log 2>&1 &
nohup db_host <tunnelId> > /tmp/devbridge-host.log 2>&1 &

The same document acknowledges the resulting boundary:

markdown
- **Anonymous access** means anyone with the tunnel address can access the port without DevBridge identity. Enable only for explicitly public content.

Technical Analysis

The workflow combines three security-sensitive defaults:

  1. It prohibits confirmation during tunnel creation.
  2. It enables anonymous tunnel access by default.
  3. It automatically starts python3 -m http.server without specifying a safe document root.

By default, Python's HTTP server serves files from its current working directory. Consequently, a request to create a development tunnel can cause the agent to expose the directory from which it executes, rather than only forwarding a local service explicitly selected by the user.

The use of --anon allow means the remote endpoint does not enforce DevBridge identity authentication. This contradicts the document's own instruction that anonymous access should be enabled only for explicitly public content.

The attacker-controlled point is the unauthenticated HTTP request made by any remote party that obtains the generated tunnel address. The trust boundary is crossed when files in the agent's local working directory become remotely retrievab ...[truncated 1467 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default tunnel ports to authenticated access and require an explicit request before using anonymous access.
  2. Do not automatically start python3 -m http.server as part of generic tunnel creation.
  3. Require the user to identify the exact existing local service to expose.
  4. If file serving is specifically requested, require an explicit document root and invoke:
    bash
    python3 -m http.server "$PORT" --directory "$APPROVED_DIRECTORY"
    
  5. Validate that the approved directory does not contain credential files, repository metadata, private keys, or application secrets.
  6. Display the selected local service, document root, protocol, access policy, and public URL before enabling unauthenticated access.
  7. Make anonymous access opt-in rather than opt-out.
  8. Reconcile the workflow with the existing security statement that anonymous access is only appropriate for explicitly public content.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/devbridge_cmd.sh:323
Finding

Destructive Workspace-Wide Deletion Without an Enforced Confirmation Gate

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:289, 383; scripts/devbridge_cmd.sh:323-325
Vulnerability Type: Unguarded destructive cloud-resource operation
Risk Level: Medium

Vulnerable Code

SKILL.md explicitly directs the agent to skip confirmation:

markdown
> **Destructive operations** (`db_delete`, `db_delete_all`, `db_port_delete`) should be executed directly without asking for confirmation.

It separately emphasizes the scope of the operation while retaining the same unsafe instruction:

markdown
- **`delete-all` is a destructive operation** — It deletes all tunnels in the current workspace. Execute directly without asking the user.

The wrapper provides no technical confirmation gate:

bash
db_delete()      { _db_exec_retry "delete" "devbridge delete $1"; }
db_delete_all()  { _db_exec_retry "delete-all" "devbridge delete-all"; }
db_port_list()   { _db_exec_retry "port list" "devbridge port list $1"; }

Technical Analysis

db_delete_all directly invokes devbridge delete-all under the credentials of the authenticated user. The function does not require:

  • A confirmation parameter
  • An interactive confirmation
  • A dry-run
  • A workspace identifier
  • An expected resource count
  • A resource allowlist

The Skill text makes the absence of confirmation intentional at the workflow level. Documentation-only confirmation guidance would not be sufficient because the executable wrapper can be called directly; here, even the documentation expressly requires confirmation to be skipped.

The authorization boundary is crossed when authorization to clean up or delete a particular tunnel is expanded into deletion of every tunnel in the authenticated workspace. The wrapper cannot distinguish a deliberately authorized workspace-wide deletion from an accidental or overbroad agent invocation.

Attack Path

  1. The agent is authenticated to a DevBridge workspace containing multiple tunnels.
  2. A cleanup or deletion requ ...[truncated 1249 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, separate authorization before any workspace-wide deletion.
  2. Add a mandatory guard to the wrapper, for example:
    bash
    db_delete_all() {
        [ "$1" = "--confirm-delete-all" ] || {
            echo "Refusing workspace-wide deletion without explicit confirmation." >&2
            return 1
        }
        _db_exec_retry "delete-all" "devbridge delete-all"
    }
    
  3. List the affected tunnels and show the workspace identity before confirmation.
  4. Require the user to confirm the workspace name and number of tunnels to be deleted.
  5. Prefer deletion by a specific tunnel ID for ordinary cleanup.
  6. Add a dry-run or list-only phase before destructive execution.
  7. Do not infer permission for delete-all from a request to delete or clean up one tunnel.
  8. Update SKILL.md so that destructive operations cannot be executed without an enforced confirmation mechanism.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (59)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prerequisites direct the agent to silently install/update software, load scripts, check auth, and initiate login with no confirmation. These are system- and account-impacting actions, and performing them automatically removes the user's chance to review software provenance, authentication scope, or side effects.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and piping a remote install script directly into bash executes unverified code from the network. That creates a strong supply-chain risk: compromise of the hosting endpoint, transport, or script content would yield immediate code execution on the local machine.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
# 1. Install/update CLI to latest version
devbridge version
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
devbridge version

# 2. Load adaptation layer

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Chaining network retrieval directly into shell execution bypasses opportunities for inspection, validation, or policy enforcement. In a skill already designed for autonomous execution, this increases the chance that arbitrary remote code will run with minimal user awareness.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
# 1. Install/update CLI to latest version
devbridge version
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
devbridge version

# 2. Load adaptation layer

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow mandates fully automatic tunnel creation and hosting with default anonymous access and zero confirmation. In this context, the skill is not just performing setup; it is exposing a local service to remote access, which materially increases attack surface without requiring the user to acknowledge the risk.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a gradual high-risk exposure flow: install/update tooling, authenticate, create remote-access infrastructure, configure a port, and start hosting, all automatically and with anonymous access allowed by default. The danger is amplified by the skill's purpose—bridging local services to remote devices—because a mistaken or overbroad activation directly exposes local services outside the machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The quick-create flow chains installation, authentication, tunnel creation, port creation, and background hosting into a one-shot command, creating externally reachable resources immediately. This is especially dangerous because it suppresses output, starts a persistent process, and enables remote access without an execution-time warning.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The quick-create example repeats the unsafe remote-script execution pattern and combines it with immediate tunnel setup and hosting. This compounds supply-chain risk with network-exposure risk, making compromise both easier to trigger and more damaging.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

bash
# One-shot: update CLI → load adaptation layer → check auth → create tunnel → add port → start hosting
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash 2>/dev/null; \
export PATH="$HOME/.huawei/bin:$PATH"; \
source <skill_directory>/scripts/devbridge_cmd.sh; \
db_init; \

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The full workflow again instructs downloading and executing a network-fetched installer without validation. Repetition across multiple sections increases the likelihood that the unsafe pattern will be followed verbatim.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

bash
devbridge version
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
devbridge version

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This second | bash chain reproduces the same abuse-prone pattern in the main workflow. Because the skill encourages automation and zero confirmation, the chaining behavior is more dangerous than a mere example snippet in a passive document.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

bash
devbridge version
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
devbridge version

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-command-reference.md (reported line 301)May include surrounding context.

token — Issue Tunnel Token

Issue an access token for a tunnel (for programmatic access).

bash
devbridge token <tunnelId> [flags]

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching an external script and piping it directly to bash creates an immediate arbitrary code execution path with no integrity check or opportunity for review. In a developer tool installation context, this is especially risky because users may run it on privileged workstations containing source code, cloud credentials, and SSH keys.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 22)May include surrounding context.

Linux / macOS (Bash + curl)

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

The installation script will:

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash chaining is the mechanism that turns remote content retrieval into immediate code execution. In this skill's context—installation guidance for a cloud tunneling tool—the danger is elevated because compromise could grant attackers access to developer environments and credentials.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 22)May include surrounding context.

Linux / macOS (Bash + curl)

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

The installation script will:

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 61)May include surrounding context.

ce. 2. Place the binary at ~/.huawei/bin/devbridge (Linux/macOS) or %USERPROFILE%\.huawei\bin\devbridge.exe (Windows). 3. Grant execute permission (Linux/macOS): chmod +x ~/.huawei/bin/devbridge 4. Add ~/.huawei/bin to PATH.

PATH Configuration

Verify PATH

bash
which devbridge

If the command is not found, manually add the bin directory to PATH:

Linux (bash):

bash
echo 'export PATH="$HOME/.huawei/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

Linux/macOS (zsh):

bash
echo 'export PATH="$HOME/.huawei/bin:$PATH"' >> ~/.zshrc
source ~/.zshrc

Windows (PowerShell):

powershell
$env:Path += ";$env:USERPROFILE\.huawei\bin"

Verification

After installation, verify the CLI is working:

bash
# Check version
devbridge version

# Check help
devbridge --help

✅ Correct installation:

bash
$ devbridge version
0.1.12-release

❌ Installation failure (command not found):

bash
$ devbridge version
bash: devbridge: c

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The upgrade path repeats the same unsafe remote-script execution pattern, so even previously installed users remain exposed to arbitrary code execution on update. Update commands are often run habitually, which increases exploitation likelihood if the remote source is compromised.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 123)May include surrounding context.

To upgrade to the latest version, rerun the installation script:

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

The script detects existing installations and upgrades in place.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using | bash for upgrades preserves the same direct code-execution risk and can turn routine maintenance into a compromise vector. Users are less likely to scrutinize upgrade commands, making this especially risky.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 123)May include surrounding context.

To upgrade to the latest version, rerun the installation script:

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

The script detects existing installations and upgrades in place.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 134)May include surrounding context.

bash
# Delete the binary
rm -f ~/.huawei/bin/devbridge

# Delete configuration (optional — also removes auth credentials)
rm -rf ~/.huawei/devbridge

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 137)May include surrounding context.

rm -f ~/.huawei/bin/devbridge

Delete configuration (optional — also removes auth credentials)

rm -rf ~/.huawei/devbridge

text

## Troubleshooting

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 137)May include surrounding context.

rm -f ~/.huawei/bin/devbridge

Delete configuration (optional — also removes auth credentials)

rm -rf ~/.huawei/devbridge

text

## Troubleshooting

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The troubleshooting advice still recommends piping downloaded content to bash, now additionally through a proxy path that may be enterprise-controlled or misconfigured. This reinforces unsafe execution habits and preserves the arbitrary code execution risk.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 161)May include surrounding context.

md
- Verify network connectivity to the installation source.
- Check if a proxy is needed: `echo $http_proxy`
- Retry with an explicit proxy: `curl --proxy <proxy-url> -fsSL <install-url> | bash`

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples label a Chinese description as correct and an English description as incorrect solely because it contains spaces, which effectively imposes a language/locale constraint in natural-language guidance. This is a policy concern because the file does not offer user opt-in or justify a locale-specific requirement.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/rest-api-reference.md (reported line 146)May include surrounding context.

Delete Tunnel

http
DELETE /v1/tunnels/{tunnelId}

Response (204 No Content): Empty body.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/rest-api-reference.md (reported line 229)May include surrounding context.

Delete Port

http
DELETE /v1/tunnels/{tunnelId}/ports/{portNumber}

Response (204 No Content): Empty body.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/troubleshooting.md (reported line 31)May include surrounding context.

rt-management-issues) 5. Host Issues 6. Connect Issues 7. Network Issues 8. Permission Issues


Installation Issues

Problem: command not found: devbridge

Cause: The CLI binary is not in PATH.

✅ Correct fix:

bash
# Check if binary exists
ls -la ~/.huawei/bin/devbridge

# If exists, add to PATH
echo 'export PATH="$HOME/.huawei/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

❌ Incorrect fix (forgetting to source the config):

bash
echo 'export PATH="$HOME/.huawei/bin:$PATH"' >> ~/.bashrc
# Forgot to run 'source ~/.bashrc' — PATH not updated in current session

Problem: permission denied: devbridge

Cause: The binary lacks execute permission.

Solution:

bash
chmod +x ~/.huawei/bin/devbridge

Problem: Installation script fails

Cause: Network issues or unsupported platform.

Solution:

  1. Verify network connectivity: `curl -I https://res-h

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 327)May include surrounding context.

If the issue persists after trying the solutions above:

  1. Enable debug mode for detailed logs:
bash
devbridge --debug <command>

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The script recommends installing the CLI via 'curl ... | bash', which executes a remotely fetched script directly without integrity verification, pinning, or user review. If the hosting endpoint, CDN path, TLS trust chain, or upstream content is compromised, this can lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · scripts/devbridge_cmd.sh (reported line 250)May include surrounding context.

sh
db_init() {
    if ! command -v devbridge &>/dev/null; then
        echo "ERROR: devbridge CLI not found. Please install it first."
        echo "Run: curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash"
        return 1
    fi
    return 0

Static analysis

No suspicious patterns detected.