Back to skill

Security audit

huawei-cloud-devkit-webui-create

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its DevKit installation purpose, but it automates high-impact cloud and root actions with unsafe package trust, SSH, network exposure, and KMS cleanup behavior that require review.

Install only on a dedicated test or disposable Huawei Cloud account/ECS with least-privilege credentials. Restrict security-group sources to your IP/VPN instead of 0.0.0.0/0, do not use custom DevKit package URLs unless the signer is independently verified, verify SSH host keys before sending root credentials, and avoid cleanup-kms unless you have confirmed the key alias/ID was created by this run.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install_devkit_webui.sh:122
Finding

Unauthenticated PKCS#7 signer permits untrusted root-level payload execution

Content
View full analysis

Vulnerability Details

File Location: scripts/install_devkit_webui.sh, lines 122-163 and 167-185
Vulnerability Type: Improper signature trust validation followed by remote code execution
Risk Level: High

Vulnerable Code

bash
wget -c "${DEVKIT_URL}" -O "${DEVKIT_PKG}" 2>&1 | tail -5
echo "Download complete ✓"

echo ""
echo "=== [3.5/6] Verify Digital Signature (.p7s) ==="
DEVKIT_SIG="${DEVKIT_PKG}.p7s"
wget -c "${DEVKIT_SIG_URL}" -O "${DEVKIT_SIG}" 2>&1 | tail -5
echo "Signature downloaded ✓"

# Verify PKCS#7 detached signature using OpenSSL
# -inform DER: .p7s files are DER-encoded
# -content: the file being signed
# -noverify: skip certificate chain validation (Huawei self-signed cert), still verifies signature-content binding
VERIFY_OK=false
if command -v openssl >/dev/null 2>&1; then
    if openssl cms -verify -inform DER -binary -in "${DEVKIT_SIG}" -content "${DEVKIT_PKG}" -noverify -out /dev/null >/dev/null 2>&1; then
        VERIFY_OK=true
    elif openssl smime -verify -inform DER -binary -in "${DEVKIT_SIG}" -content "${DEVKIT_PKG}" -noverify -out /dev/null >/dev/null 2>&1; then
        VERIFY_OK=true
    fi
fi

if [[ "${VERIFY_OK}" == "true" ]]; then
    echo "Digital signature verification PASSED ✓"
else
    echo "⚠️  Digital signature verification FAILED!"
    exit 1
fi

mkdir -p DevKit-All
tar -xzf "${DEVKIT_PKG}" -C DevKit-All

cd DevKit-All/${DEVKIT_DIR}
...
spawn bash install.sh -a

Technical Analysis

The script downloads both the DevKit archive and its detached .p7s signature from the same externally supplied location. It then invokes OpenSSL with -noverify, which verifies that the signature mathematically matches the archive but does not establish that the signing certificate belongs to Huawei or chains to an approved trust anchor.

Consequently, a source capable of supplying both files can generate its own certificate, sign an arbitrary archive, and satisfy this check. The archive is extracted and its `insta ...[truncated 1348 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin an approved Huawei signing certificate, public key, or certificate fingerprint in the Skill.
  • Remove -noverify and validate the signer against a controlled trust store and expected signer identity.
  • If a private or self-signed vendor certificate is required, distribute that certificate through the audited Skill package or another authenticated channel and pass it explicitly as the trust anchor.
  • Do not obtain both the payload and its sole trust material from the same configurable URL.
  • Restrict custom package URLs unless the user also supplies separately authenticated trust material.
  • Validate archive members before extraction to reject absolute paths, .. traversal, links escaping the extraction directory, and unexpected executable entry points.
  • Abort before extraction or execution whenever publisher authentication cannot be completed.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/create_ecs_and_setup_devkit.py:145
Finding

Fallback KMS selection can disable and delete an unrelated account key

Content
View full analysis

Vulnerability Details

File Location: scripts/create_ecs_and_setup_devkit.py, lines 145-167 and 507-526
Vulnerability Type: Destructive operation on a resource without ownership validation
Risk Level: High

Vulnerable Code

python
def kms_create_key(kms_client):
    key_alias = f"devkit-ecs-pwd-{uuid.uuid4().hex[:8]}"
    try:
        body = CreateKeyRequestBody(
            key_alias=key_alias,
            key_spec="AES_256",
            key_usage="ENCRYPT_DECRYPT",
        )
        req = CreateKeyRequest(body=body)
        resp = kms_client.create_key(req)
        if resp.key_info and resp.key_info.key_id:
            return resp.key_info.key_id
    except Exception as e:
        print(f"  WARNING: KMS key creation failed ({e}), trying existing keys...", file=sys.stderr)
    try:
        list_body = ListKeysRequestBody(limit=10)
        list_req = ListKeysRequest(body=list_body)
        list_resp = kms_client.list_keys(list_req)
        keys = list_resp.keys if hasattr(list_resp, "keys") else []
        if keys:
            return keys[0].key_id
    except Exception:
        pass
    return None

The selected key is later passed to the destructive cleanup path:

python
def phase_cleanup_kms(args):
    credentials = get_credentials()
    kms_client = KmsClient.new_builder().with_credentials(credentials).with_region(
        KmsRegion.value_of(args.region)
    ).build()

    print(f"[1/2] Disabling KMS key {args.kms_key_id} (password immediately unrecoverable)...")
    try:
        kms_disable_key(kms_client, args.kms_key_id)
        print(f"  KMS key {args.kms_key_id} disabled. Password no longer recoverable.")
    except Exception as e:
        print(f"  WARNING: KMS key disable failed ({e}).", file=sys.stderr)
        if not args.force:
            sys.exit(1)

    print(f"[2/2] Scheduling KMS key deletion ({args.delay_days} days, API minimum is 7)...")
    try:
        kms_schedule_deletion(kms_client, args.kms_key_id, delay_da
...[truncated 2125 chars]
Remediation
View remediation

Remediation Suggestions

  • Fail closed when creation of the dedicated KMS key fails; never fall back to an arbitrary existing key.
  • Apply a unique workflow identifier and ownership tags when creating the key.
  • Persist the expected key ID and ownership metadata in a workflow state file protected against modification.
  • Before disabling or deleting a key, retrieve its metadata and verify its alias, tags, region, and workflow identifier.
  • Record whether the key was newly created or externally supplied. Never automatically delete externally supplied keys.
  • Require explicit user confirmation that displays the validated DevKit alias and key ID before destructive cleanup.
  • Remove or tightly constrain --force; it must not bypass ownership validation.
  • Grant the runtime identity permission to manage only keys tagged for this workflow where the cloud IAM model supports such restrictions.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_ecs_and_setup_devkit.py:210
Finding

SSH host-key verification is disabled before root password authentication

Content
View full analysis

Vulnerability Details

File Location: scripts/create_ecs_and_setup_devkit.py, lines 210-214 and 445-449
Vulnerability Type: Missing SSH server authentication
Risk Level: Medium

Vulnerable Code

The installation connection automatically trusts any previously unknown host key:

python
def ssh_install_devkit(eip, password, devkit_url, install_path="", install_port="", wait=False):
    import paramiko
    ssh = paramiko.SSHClient()
    ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
    try:
        ssh.connect(eip, port=22, username="root", password=password, timeout=30)

The status connection repeats the same behavior:

python
def _ssh_connect_with_kms(eip, kms_key_id, kms_cipher_text_file, region):
    ...
    ssh = paramiko.SSHClient()
    ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
    try:
        ssh.connect(eip, port=22, username="root", password=password, timeout=15)

Technical Analysis

paramiko.AutoAddPolicy() accepts and stores an unknown SSH host key without independently verifying that it belongs to the intended ECS. The connection then authenticates as root using the password decrypted from KMS.

SSH host-key verification is the control that prevents a network endpoint from impersonating the target server. Automatically accepting an unknown key removes that protection on the first connection. Encryption remains active, but it is established with whichever endpoint supplied the accepted key.

The issue affects both installation and status polling, so multiple workflow stages can disclose the credential to an impersonating endpoint.

Attack Path

  1. An attacker gains the ability to intercept, redirect, or spoof traffic between the machine running the Skill and the selected ECS public IP.
  2. The attacker presents an SSH server with an arbitrary host key.
  3. AutoAddPolicy() accepts the key without matching it against a trusted fingerprint.
  4. Paramiko attempts root password authentic ...[truncated 640 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace paramiko.AutoAddPolicy() with paramiko.RejectPolicy().
  • Obtain the ECS SSH host-key fingerprint through a trusted provisioning or cloud control-plane channel.
  • Create a dedicated known-hosts file for the workflow and load it with SSHClient.load_host_keys().
  • Verify the expected hostname or IP and key fingerprint before sending the root password.
  • Treat a missing or changed host key as a hard failure requiring explicit investigation, not automatic acceptance.
  • Prefer short-lived SSH keys or cloud-issued temporary access over a reusable root password where supported.
  • Apply the same verification policy to installation, status polling, and every retry path.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description emphasizes a broader automation workflow on Huawei Cloud: provisioning a new Kunpeng ECS, handling credentials securely with KMS, performing EIP/VPC operations, and connecting via Paramiko SSH to install DevKit. The supplied code does none of those cloud-management or remote-access tasks. Instead, it is a host-local Bash installer that prepares the machine, downloads and signature-verifies the DevKit package, runs install.sh noninteractively via Expect, and checks local services. The overlap is that it does install Kunpeng DevKit WebUI mode with plugins, but the primary surrounding capabilities in the description are absent, making the description materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an installer/provisioning skill for deploying Kunpeng DevKit on Huawei Cloud, including cloud resource creation, credential handling, encryption, networking, SSH, and package installation. The supplied code chunk does none of those things. It is a post-installation verification script that inspects systemd service status, listening ports, filesystem paths, plugin directories, and WebUI availability. While the verification targets the same product domain (Kunpeng DevKit WebUI), the primary purpose is materially different from installation/provisioning, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The acceptance criteria explicitly use curl -k, which disables TLS certificate verification and can normalize insecure behavior when validating the DevKit WebUI. In a cloud installation workflow, this can allow man-in-the-middle interception or make users accept spoofed HTTPS endpoints, especially if they later reuse the pattern beyond a one-off local test.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 138)May include surrounding context.

WebUI Access

bash
curl -k https://<ECS_IP>:8086 -I
# Expected: HTTP/1.1 302 or 200

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 33)May include surrounding context.

I) Installation

Auto Install (Recommended)

bash
bash skills/hcloud-cli/scripts/install.sh

Features:

  • Auto-detect OS and CPU architecture (x86_64/aarch64)
  • No sudo required, installs to ~/.local/bin/
  • Downloads latest version from Huawei Cloud official OBS

Configure PATH after installation:

bash
export PATH="$PATH:$HOME/.local/bin"

# Permanent addition to ~/.bashrc
echo 'export PATH="$PATH:$HOME/.local/bin"' >> ~/.bashrc
source ~/.bashrc

macOS

bash
# Install via Homebrew
brew install hcloudcli

# Or download directly
curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz
tar -xzf hcloudcli-macos-amd64.tar.gz
chmod +x hcloud
sudo mv hcloud /usr/local/bin/

Linux (x86_64)

bash
curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-linux-amd64.tar.gz
tar -xzf hcloudcli-linux-amd64.tar.gz
chmod +x hcloud
sudo mv hcloud /usr/local/bin/
`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/devkit-installation-workflow.md (reported line 185)May include surrounding context.

md
> - **Timeout**: 600s watchdog prevents indefinite hang
> - **Monitor**: `tail -f /tmp/devkit_install.log` — real-time log
> - **Status**: `kill -0 $(cat /tmp/devkit_install.pid) 2>/dev/null && echo RUNNING || echo STOPPED`
> - **Abort**: `kill $(cat /tmp/devkit_install.pid)` then `rm -f /tmp/devkit_install.pid`

> **⚠️ Critical: expect matching order**
>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The command curl -k https://localhost:8086 -I abuses a security-relevant tool parameter by disabling certificate verification for an HTTPS endpoint. In a cloud installation skill that provisions and exposes a WebUI, this is more dangerous because operators may copy the pattern to test public endpoints, suppressing detection of invalid, spoofed, or intercepted TLS sessions.

Content

Scanner excerpt · references/verification-method.md (reported line 131)May include surrounding context.

7. WebUI Access Verification

bash
# Local curl verification of HTTPS port
curl -k https://localhost:8086 -I
# Expected: HTTP/1.1 302 or 200

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The end-to-end script silently uses curl -k to determine success, which means the verification process will report the WebUI as reachable even when TLS authenticity cannot be established. This can hide certificate deployment errors and trains automation to accept insecure HTTPS, weakening security controls in a cloud-hosted administrative interface.

Content

Scanner excerpt · references/verification-method.md (reported line 191)May include surrounding context.

md
echo ""
echo "[5] WebUI Access"
http_code=$(curl -k -s -o /dev/null -w "%{http_code}" https://localhost:8086 2>/dev/null || echo "000")
check "WebUI (HTTP $http_code)" "$([ "$http_code" == "200" ] || [ "$http_code" == "302" ] && echo ok || echo fail)"

echo ""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/verify_devkit.sh (reported line 59)May include surrounding context.

sh
webui_ok=fail
for target in localhost "${INTERNAL_IP}"; do
    [[ -z "$target" ]] && continue
    http_code=$(curl -k -s -o /dev/null -w "%{http_code}" "https://${target}:8086" 2>/dev/null || echo "000")
    if [[ "$http_code" == "200" ]] || [[ "$http_code" == "302" ]]; then
        webui_ok=ok
        echo "  ✅ WebUI via ${target} (HTTP $http_code)"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes use of sensitive capabilities including environment-variable access, file reads/writes, and shell execution, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an overbroad execution surface where an agent may invoke more capabilities than reviewers or operators expect, which is especially risky because the workflow handles cloud credentials, KMS operations, remote SSH, and resource provisioning.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The workflow explicitly instructs launching installation and polling processes with nohup in the background, creating session-persistent activity that can continue after user interaction ends. In a cloud-provisioning and remote-installation context, this can lead to uncontrolled resource modification, incomplete observability, lingering processes, and a harder-to-audit execution trail if the agent disconnects or loses state.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
1. **2a. KMS decrypt** — Python SDK reads cipher text from file and decrypts password from `kms_key_id`
2. **2b. paramiko SSH connect** — `SSHClient.connect(password=decrypted)` — password in Python memory only
3. **2c. Upload scripts** — SFTP upload `install_devkit_webui.sh`, `auto_install_devkit.expect`, `verify_devkit.sh` to `/tmp/`
4. **2d. Start DevKit install** — Execute `nohup bash /tmp/install_devkit_webui.sh <url> &` on remote ECS (background)
5. **2e. Poll install progress** — Launch `poll_devkit_status.py` in background (output to log file), then use `read` tool with incrementing offset to read the log every 10-20s and report to user (doom-loop safe, continuous visibility; see Polling Progress below)
6. **2f. Verify installation** — Run `verify_devkit.sh` and check results
7. **2g. Report result** — If verification passed, prompt agent to proceed to Task 4 (cleanup-kms); if failed, KMS key is preserved for retry

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 24)May include surrounding context.

md
**Features:**
- Auto-detect OS and CPU architecture (x86_64/aarch64)
- No sudo required, installs to `~/.local/bin/`
- Downloads latest version from Huawei Cloud official OBS

**Configure PATH after installation:**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 47)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 56)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 65)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 119)May include surrounding context.

md
> **Security warning**: Method 3 will expose AK/SK in command history; only use in secure environments.

> **Prohibited actions:**
> - Do not ask the user to provide AK/SK directly in the conversation
> - Do not extract AK/SK from hcloud config files (credentials are encrypted)
> - Do not use `hcloud configure set` with plaintext AK/SK values in conversation

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide recommends piping "y" into the CLI to auto-accept the privacy policy, which bypasses explicit user review and consent. While not a code-execution issue, it normalizes silent acceptance of legal/security prompts and can lead users to approve terms without understanding data handling implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide states the one-click installer runs on the target ECS but does not clearly and prominently warn that the automated flow may authorize firewall changes during installation. Silent or poorly disclosed network exposure can cause operators to open service ports they did not intend, increasing attack surface for the newly installed WebUI and related services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The automatic security group configuration explicitly opens both SSH (22) and the DevKit WebUI port (8086) to 0.0.0.0/0, exposing the host and management interface to the entire internet. In this skill's context, that is particularly risky because it provisions a fresh cloud instance intended for remote administration, making it an attractive target for scanning, brute force attempts, and exploitation of any WebUI or SSH weakness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/devkit-installation-guide.md (reported line 61)May include surrounding context.

Linux:

bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/devkit-installation-guide.md (reported line 355)May include surrounding context.

Linux:

bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/devkit-installation-workflow.md (reported line 161)May include surrounding context.

Linux:

bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/polling-progress-guide.md (reported line 15)May include surrounding context.

Linux:

bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/create_ecs_and_setup_devkit.py (reported line 223)May include surrounding context.

python
**Linux:**
```bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/create_ecs_and_setup_devkit.py (reported line 500)May include surrounding context.

python
**Linux:**
```bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install_devkit_webui.sh (reported line 225)May include surrounding context.

sh
**Linux:**
```bash
nohup python3 scripts/poll_devkit_status.py \
  --region $R --eip $EIP --kms-key-id $KID --kms-cipher-text-file $CT_FILE \
  --interval 30 --max-polls 30 \
  --log-file /tmp/devkit_poll_progress.log &

Static analysis

No suspicious patterns detected.