Back to skill

Security audit

huawei-cloud-dws-dymem-diag

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a Huawei DWS memory-diagnosis workflow, but it needs Review because it handles cloud credentials and sensitive diagnostic data while under-disclosing local persistence and some credential-handling risks.

Install only if you are comfortable giving the agent read access to Huawei DWS monitoring data, active SQL/session details, host/IP metadata, and a local workspace report. Prefer interactive or managed-secret credential setup, avoid passing AK/SK on the command line, keep generated reports out of shared or version-controlled folders, and use least-privilege read-only IAM permissions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CLI example passes AK/SK directly as command-line arguments, which can expose secrets via shell history, process listings, audit logs, CI logs, and support screenshots. This is a well-known credential handling risk, and the absence of a warning makes it likely users will follow the unsafe example verbatim.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language trigger wording is ambiguous and lacks strict scope boundaries, which raises the risk of accidental invocation on ordinary memory-support requests. In an agent environment, accidental activation matters because the skill includes external tool use and local execution instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger keyword set is broad enough to activate on generic memory-related troubleshooting requests, increasing the chance that the skill runs outside the intended DWS-cluster context. Overbroad activation can lead to unnecessary environment probing, tool calls, or report generation in unrelated conversations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promises output-only behavior but also instructs writing an HTML file to the local workspace, creating an undeclared side effect. Silent local file creation can violate least surprise, overwrite artifacts, or expose potentially sensitive diagnostic content to other processes or users on the host.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation creates a trust mismatch by stating the output only contains the diagnosis report while elsewhere requiring a local file write. This inconsistency can cause operators or orchestrators to grant the skill broader access than intended or miss that it performs persistent actions on the host filesystem.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
- Valid Huawei Cloud credentials (AK/SK mode or IAM Token)
- **Security Rules**:
  - Never expose AK/SK values in conversations or commands
  - Never ask users to input AK/SK directly in conversation
  - Only use `hcloud configure list` to check credential status

### 4. IAM Permission Requirements

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs executing local shell and Python commands for environment probing and timestamp conversion, which expands its capability beyond remote diagnostics into arbitrary local command execution. Even if the examples are simple, allowing shell/Python execution in a skill increases attack surface and can be abused in environments where command execution is sensitive or insufficiently sandboxed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs saving an HTML report into the workspace without a clear user-facing warning or consent mechanism. Writing diagnostic reports locally may persist sensitive infrastructure metadata, SQL text, usernames, and memory details in shared or monitored storage.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 404)May include surrounding context.

md
## Notes

- **Security**: Never expose AK/SK values in conversations or commands; never ask users to input AK/SK directly in conversation
- **Time Protocol**: from_ts/to_ts must use millisecond timestamps; report displays Beijing time; when converting Beijing time to timestamp, must append +08:00 timezone suffix; do not mentally calculate timestamp values; do not convert existing millisecond timestamps to time strings and then back
- **Output Constraints**: Strictly output the diagnosis report following the Output Format section template; do not modify template structure, do not omit any part, do not add remediation suggestions, do not output SQL optimization statements, do not use emoji, do not use custom format tags
- **Data Authenticity**: All diagnosis conclusions must come from actual tool return results; when tool returns empty or call fails, mark as "unavailable"; fabricating values is prohibited

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 27)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 36)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly instructs users to place plaintext AK/SK credentials into a configuration file before startup, but does not warn about secure handling, file permissions, secret rotation, or avoiding accidental commit/log exposure. Even if the server later auto-encrypts the values, the secrets exist in plaintext at rest and may be exposed through editors, backups, version control, or local filesystem access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dws-mcp-installation-guide.md (reported line 99)May include surrounding context.

Other Commands

bash
# Manually trigger encryption (auto-executed on MCP Server startup as well)
python -m dws_autopilot_mcp.config_cli encrypt

# Show config status (secrets are masked as ******)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The HTML template explicitly sets lang="zh-CN", and the surrounding instructions require strict adherence to this Chinese-language output format. This imposes a specific language/locale on all outputs with no opt-in, alternative locale, or documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instructions require all report timestamps to be converted to Beijing time (UTC+8), which imposes a specific locale/timezone format on all users. The file does not offer opt-in, user selection, or a clear justification that this skill is restricted to a China-region operational context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.