Back to skill

Security audit

huawei-cloud-dws-cpu-diag

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only Huawei DWS CPU diagnosis workflow, but its supporting installation docs introduce unrelated OBS storage tooling and risky credential-handling steps.

Review the installation docs before use. Install only the DWS-required hcloud or DWS MCP components, avoid the OBS/obsutil setup unless you independently need it, and do not pass AK/SK secrets on command lines. Use least-privilege DWS read-only IAM permissions and handle the generated HTML report as sensitive operational data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
- Valid Huawei Cloud credentials (AK/SK mode or IAM Token)
- **Security Rules**:
  - Never expose AK/SK values in conversations or commands
  - Never ask users to input AK/SK directly in conversation
  - Only use `hcloud configure list` to check credential status

### 4. IAM Permission Requirements

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
### Step 4: Query CPU Highest Node Diagnosis Details

Call metric query with metric_name="cpu_io_diagnose_detail". Does not support host_id filtering; query full cluster then filter by nodes_to_analyze from Step 1 output. **MCP mode must use limit=200 paginated query** (this metric has the largest data volume; single page of 800 will exceed token limit), until returned count < 200, merge all paginated data before filtering.

**Parsing**: Extract active queries, users, duration, process information. ctime is collection time, not SQL start time; when duration_ms exists, SQL start time = ctime - duration_ms. Only count users with state=active. inst_name contains "cn" → CN instance; contains "dn" → DN instance.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as producing a diagnosis report, but it also instructs writing an HTML file into the local workspace. That creates an undeclared side effect on the host filesystem, which can leak sensitive operational data into persistent storage, surprise callers that expect read-only behavior, and violate least-privilege expectations for an analysis skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output format hard-codes lang="zh-CN" and the entire report template in Chinese, and elsewhere the skill requires all timestamps to be converted to Beijing time. This imposes a specific language/locale on all users without opt-in, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

md
## Notes

- **Security**: Never expose AK/SK values in conversations or commands; never ask users to input AK/SK directly in conversation
- **Time Protocol**: from_ts/to_ts must use millisecond timestamps; report displays Beijing time; when converting Beijing time to timestamp, must append +08:00 timezone suffix; do not mentally calculate timestamp values; do not convert existing millisecond timestamps to time strings and then back
- **Output Constraints**: Strictly output the diagnosis report following the Output Format section template; do not modify template structure, do not omit any part, do not add remediation suggestions, do not output SQL optimization statements, do not use emoji, do not use custom format tags
- **Data Authenticity**: All diagnosis conclusions must come from actual tool return results; when tool returns empty or call fails, mark as "无法获取"; fabricating values is prohibited

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide is for OBS Object Storage Statistics rather than the declared DWS CPU diagnosis skill, indicating a capability/scope mismatch. This can mislead operators into installing and configuring unrelated tooling and credentials, expanding access beyond what the skill should need and increasing the chance of misuse or accidental data exposure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 27)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 36)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 67)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 76)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 85)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide adds OBS-specific tooling and bucket-access verification for a skill whose stated purpose is DWS CPU diagnosis. Introducing unrelated storage tooling and authentication steps increases the attack surface and may cause users to provision unnecessary credentials or grant broader permissions than needed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The obsutil configuration example places AK/SK directly on the command line, which can leak secrets through shell history, process listings, terminal logging, and audit tooling. In a cloud operations context, exposed long-lived credentials could allow unauthorized access to OBS resources and potentially broader tenant data depending on IAM scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to pass AK/SK directly as command-line arguments, which can expose secrets through shell history, process listings, audit logs, and CI/CD job output. Even though the document mentions later encryption at rest, that does not protect credentials during entry, so the installation guidance creates a real secret-handling risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dws-mcp-installation-guide.md (reported line 99)May include surrounding context.

Other Commands

bash
# Manually trigger encryption (auto-executed on MCP Server startup as well)
python -m dws_autopilot_mcp.config_cli encrypt

# Show config status (secrets are masked as ******)

Static analysis

No suspicious patterns detected.