Back to skill

Security audit

huawei-cloud-devkit-application-check-cli

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Huawei Cloud migration-assessment workflow, but it performs high-impact cloud provisioning, SSH access, credential handling, uploads, and installs with inconsistent consent boundaries and unsafe SSH host verification.

Install only if you intend the agent to manage Huawei Cloud resources, create or reuse an ECS instance, SSH into it, upload and run scripts, install DevKit/Maven/JDK dependencies, handle target-server SSH credentials, and download scan reports. Require a separate confirmation before SSH/upload/install/scan steps, verify SSH host fingerprints out of band, use least-privileged cloud credentials, and rotate or remove stored passwords after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/devkit_remote.py:206
Finding

Unauthenticated SSH Connection to the Privileged DevKit Server

Content
View full analysis

Vulnerability Details

File Location: scripts/devkit_remote.py, lines 206–211
Vulnerability Type: SSH host-key verification bypass
Risk Level: High

Complete Code Snippet:

python
def get_ssh_client(host, user, password, retries=3, delay=10):
    client = paramiko.SSHClient()
    client.set_missing_host_key_policy(paramiko.AutoAddPolicy())
    last_err = None
    for attempt in range(1, retries + 1):
        # ...
        try:
            client.connect(host, port=22, username=user, password=password, timeout=15)
            return client, user, password

Technical Analysis

paramiko.AutoAddPolicy() accepts and records any previously unknown SSH host key without validating it through a trusted fingerprint or pre-provisioned known_hosts entry. Consequently, possession of the expected network address is treated as sufficient proof of server identity.

This function is the common connection path for operations that check the server, upload scripts, install DevKit, run scans, and download reports. The connection uses the privileged DEVKIT_ECS_USER and DEVKIT_ECS_PASSWORD credentials. Although the project redacts the password from output, output redaction does not protect it from a server impersonating the intended SSH endpoint during password authentication.

Attack Path

  1. The user or Agent invokes an operation such as check, upload, install, scan, download-report, login, or full.
  2. get_ssh_client() connects to the selected or automatically resolved ECS address.
  3. An attacker with network interception, routing, DNS, address-redirection, or equivalent man-in-the-middle capability presents a fraudulent SSH server and arbitrary host key.
  4. AutoAddPolicy() accepts the attacker's unknown key without warning or trusted verification.
  5. Password authentication exposes the DevKit ECS credential to the impersonating endpoint.
  6. The attacker can impersonate the ECS, receive uploaded scripts and commands, retu ...[truncated 671 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace paramiko.AutoAddPolicy() with paramiko.RejectPolicy().
  • Load host keys from a dedicated, permission-restricted known_hosts file before connecting.
  • Obtain the ECS host-key fingerprint through a trusted provisioning channel, cloud-console metadata, or another authenticated out-of-band mechanism.
  • Pin the expected key to the specific ECS identity and reject both unknown and changed keys.
  • Do not silently retry after a host-key mismatch; terminate the operation and report a sanitized error.
  • Where available, prefer key-based client authentication with a dedicated, least-privileged account, while retaining strict server host-key verification.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/encrypt-nodes-verify.sh:321
Finding

Target-Server Credentials Exposed by Disabled SSH Host Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/encrypt-nodes-verify.sh, lines 321–331
Vulnerability Type: SSH host-key verification bypass during password authentication
Risk Level: High

Complete Code Snippet:

bash
if command -v sshpass >/dev/null 2>&1; then
    SSHPASS="${ssh_pass}" sshpass -e ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null \
        -o ConnectTimeout=${timeout} -p "${ssh_port}" "${ssh_user}@${host_ip}" "echo OK" 2>/dev/null
    return $?
fi

if command -v expect >/dev/null 2>&1; then
    expect -c "
set timeout ${timeout}
spawn ssh -o StrictHostKeyChecking=no -p ${ssh_port} ${ssh_user}@${host_ip} echo OK
expect {
    \"*assword*\" { send \"${ssh_pass}\r\"; exp_continue }
    \"OK\" { exit 0 }
    timeout { exit 1 }
}
" 2>/dev/null

Technical Analysis

Both password-based verification paths explicitly disable SSH server authentication:

  • The sshpass path sets StrictHostKeyChecking=no and discards host-key state through UserKnownHostsFile=/dev/null.
  • The expect fallback also sets StrictHostKeyChecking=no.

The script therefore sends each plaintext target password to whichever SSH server answers at the configured target address, without verifying that server's cryptographic identity. This occurs during the pre-scan verification stage, before plaintext passwords are replaced in nodes.conf.

Using sshpass -e prevents the password from appearing directly in the command-line argument list, but it does not prevent disclosure to an unauthenticated remote endpoint. Password encryption performed after verification also cannot undo credentials already disclosed during a man-in-the-middle session.

Attack Path

  1. A scan or explicit encryption-and-verification workflow processes a target entry from nodes.conf.
  2. The entry contains a plaintext ssh_pass, so verify_ssh() attempts password authentication before encryption.
  3. An attacker capable of intercepting or redirecting traffic t ...[truncated 1173 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove StrictHostKeyChecking=no and UserKnownHostsFile=/dev/null from both verification paths.
  • Maintain a dedicated, permission-restricted known_hosts file on the DevKit ECS.
  • Require users or administrators to provision and confirm each target server's fingerprint through an authenticated out-of-band channel before password verification.
  • Invoke SSH with strict checking, for example using StrictHostKeyChecking=yes and an explicit UserKnownHostsFile.
  • Abort on unknown or changed host keys; never treat such failures as ordinary connectivity errors or silently continue to encryption and scanning.
  • Prefer public-key authentication with per-target, least-privileged scan accounts where supported.
  • Bind verification state to both target identity and fingerprint rather than recording only the IP address.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk does not implement the declared migration-assessment workflow. Its primary purpose is credential handling and connectivity verification for target nodes, not collection of installed software, Maven compatibility analysis, report generation, or automated cloud server provisioning/install/scan orchestration. While SSH verification could be a supporting step in a larger DevKit workflow, the concrete behavior here is materially different and includes undeclared capabilities: reading target host credentials, attempting SSH logins, encrypting stored passwords, and modifying configuration files. Those are security-relevant actions not reflected in the description. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code’s actual behavior is narrowly focused on environment setup and installation: installing dependencies, downloading the DevKit package, configuring PATH, verifying the binary, and optionally preparing Maven/JDK. Those are supporting setup actions consistent with part of the description ('installs DevKit'), so that portion matches. However, the description also claims substantive operational capabilities—software information collection, Maven compatibility analysis, report generation, automatic ECS server creation, script upload, and scan execution—which are absent from this code chunk. Because several core declared functions are not represented here, especially the infrastructure automation and scan/report actions, the description overstates what the supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The core scanning behavior aligns well with the declared migration-assessment functions: collecting system/software information, running Maven migration analysis, running container migration analysis, and producing reports. However, the description also claims infrastructure/orchestration capabilities—automatic Kunpeng ECS server creation, script upload, and DevKit installation on request—that are not present in this code chunk. This script explicitly states it runs manually on the DevKit server, detects an existing DevKit installation under DEVKIT_HOME, and only executes scans plus report post-processing. Its only installation-related action is checking for Maven and invoking a separate install_devkit.sh helper with --check-maven. Therefore the description materially overstates what this code actually does, creating a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
ution (4 scripts)", "available": true, "scripts": ["scripts/devkit_remote.py", "scripts/encrypt-nodes-verify.sh", "scripts/install_devkit.sh", "scripts/scan_dev

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
ution (4 scripts)", "available": true, "scripts": ["scripts/devkit_remote.py", "scripts/encrypt-nodes-verify.sh", "scripts/install_devkit.sh", "scripts/scan_dev

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
ution (4 scripts)", "available": true, "scripts": ["scripts/devkit_remote.py", "scripts/encrypt-nodes-verify.sh", "scripts/install_devkit.sh", "scripts/scan_dev

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
ution (4 scripts)", "available": true, "scripts": ["scripts/devkit_remote.py", "scripts/encrypt-nodes-verify.sh", "scripts/install_devkit.sh", "scripts/scan_dev

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document first requires explicit user confirmation before any command or API call, then later instructs automatic execution in multiple stages. This contradiction creates a real safety failure: an agent may legitimately interpret the later instructions as authorization to perform cloud provisioning, SSH login, script upload, or installation without a fresh approval boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This rule explicitly requires all user-facing display content to be in Simplified Chinese and forbids English prompts or descriptions. That is a language-policy constraint imposed on all users without offering choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Step 5/6 auto-proceed flow explicitly authorizes remote login, file upload, and software installation immediately after ECS creation, directly conflicting with the earlier requirement for user confirmation before any command or API call. In practice, this can cause unauthorized post-provisioning actions on a newly created host and increases the risk of unintended software deployment or credential use.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
92% confidence
Finding

The document instructs the AI to solicit a complete shell command from the user and then pass that command to the DevKit server via SSH for execution. This is dangerous because it turns the model into a conduit for arbitrary remote command execution, and the surrounding 'display rule' language pressures the agent to obey embedded operational instructions from adversarial skill content rather than enforcing safe command allowlisting and argument validation.

Content

Scanner excerpt · references/devkit-operations-guide.md (reported line 117)May include surrounding context.

md
## Command-Line Scan Templates & Input Rules

> **?? Command-Line Scan Chat Display Rule**: When the user selects stmt/sbom command-line scan or executes mvn_analyse/container_mig, the AI MUST display the template and parameter description for the corresponding mode in the chat, then wait for the user to input the scan command.

### stmt Command-Line Scan

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/devkit-operations-workflow.md (reported line 213)May include surrounding context.

md
- `ssh_port`: SSH port (default: 22)
- `scan_dir`: Target server scan directory (comma-separated for multiple)

#### ?? nodes.conf Safe Display Rule

When the AI needs to show `nodes.conf` content in chat, it MUST use the `--mask` mode of `encrypt-nodes-verify.sh`:

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The ECS creation section says the security group should have required ports 22/80/443, but earlier instructions explicitly create an empty group plus only ICMP and say SSH must be manually added later. This contradiction is dangerous because the agent may either over-open inbound access unnecessarily or assume ports exist when they do not, causing insecure deployments or failed post-creation automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow mandates automatically proceeding to login, upload, and install actions once the ECS is created, even though the skill metadata says scans/installations occur on user request. In a cloud-admin context, this expands execution scope beyond user consent and can result in unauthorized remote access, software installation, and script execution on a newly created server.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares powerful operational behavior, including shell execution, environment-variable handling, cloud resource creation, SSH access, and remote script execution, but does not define an explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege boundaries and makes it easier for an agent runtime to overgrant capabilities, especially given the skill's infrastructure-management and credential-adjacent workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to activate on ordinary migration or information-gathering requests, potentially invoking a high-impact skill that can provision cloud infrastructure, handle credentials, and perform remote scanning. Over-broad invocation increases the chance of accidental execution in contexts where the user only wanted advice, not operational actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section says to never create temporary script files and even lists devkit_remote.py as an example of something that must not be created, while the manifest metadata and earlier command-mode table explicitly declare scripts/devkit_remote.py as a supported script used by the skill. That is not merely incomplete documentation; it actively conflicts with the described implementation approach.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically moving from ECS creation into SSH login, script upload, and installation without a distinct user-facing warning reduces informed consent for sensitive actions. In this skill's context, those actions are especially risky because they involve remote host access, software deployment, and credential use on cloud infrastructure that may incur cost and operational impact.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scan section says scanning can proceed after Step 7 passes, which conflicts with the earlier explicit statement that scans are only run on explicit user request. Because scans may access remote systems, collect software inventories, and process credential-protected targets, ambiguity here can lead to unauthorized reconnaissance or data collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly requires the workflow to proceed automatically into SSH login verification, script upload, and remote installation on a newly created ECS instance without an additional explicit warning or confirmation. In a skill that provisions cloud infrastructure and performs remote system modification, this increases the risk of users triggering privileged actions they did not fully understand, leading to unexpected resource creation, software installation, and broader trust in subsequent remote actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The acceptance criteria endorse automatic continuation from ECS creation directly into remote login, file upload, and execution of install_devkit.sh with no additional confirmation. Because this skill handles cloud credentials, passwords, and remote execution, removing the confirmation boundary makes accidental or overly broad privileged changes more likely and normalizes unattended system modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to download and immediately execute a remote shell installer via bash ./hcloud_install.sh without integrity verification, signature checking, or any warning about trust and system modification. If the hosting location, network path, or script is compromised, this becomes arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 88)May include surrounding context.

md
1. Log in to Huawei Cloud console: https://console.huaweicloud.com/
2. Click avatar in upper right corner → My Credentials
3. Select Access Keys from the left panel
4. Click Create Access Key
5. Download CSV file (contains AK and SK)

### Check AK/SK Configuration Status

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide tells users to place cloud AK/SK into persistent environment variables or CLI configuration and provides exact commands/templates, but does not adequately warn about plaintext storage, shell history, process inspection, profile leakage, or multi-user host exposure. These are long-lived cloud credentials for infrastructure operations, so mishandling can lead to account compromise and unauthorized resource creation or access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document first says the AI must never read AK/SK from environment variables and write them into an hcloud profile, but later defines environment variables as a credential fallback source. That contradiction can lead an implementer or downstream agent to consume long-lived cloud credentials from the environment despite earlier safety constraints, increasing the chance of unintended credential handling or leakage in tooling and logs.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
references/ecs-creation.md:229