Back to skill

Security audit

huawei-cloud-dws-io-diag

Security checks for vulnerabilities and agentic risk

Overview

The skill is relevant for DWS I/O diagnosis, but it needs review because it handles cloud credentials and detailed database telemetry with under-scoped storage and reporting practices.

Install only in an environment where the operator is authorized to view DWS production telemetry and SQL text. Prefer interactive or secret-manager credential setup, avoid putting AK/SK values in command lines or plaintext files, restrict file permissions, and treat generated HTML reports as sensitive operational records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CLI example passes the access key and secret key directly as command-line arguments, which can leak via shell history, process listings, terminal logging, CI logs, and monitoring tools. Because these are cloud credentials, disclosure could allow unauthorized API access to the user's Huawei Cloud resources.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- Valid Huawei Cloud credentials (AK/SK mode or IAM Token)
- **Security Rules**:
  - Never expose AK/SK values in conversations or commands
  - Never ask users to input AK/SK directly in conversation
  - Only use `hcloud configure list` to check credential status

### 4. IAM Permission Requirements

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs execution of local Python one-liners to read conf/dws_config.yaml and format timestamps. That expands the skill from using declared DWS diagnostic tools into arbitrary host-side command execution, which can access local files and interpreter capabilities outside the manifest's allowed tools. In a skill file treated as adversarial input, this is dangerous because it normalizes shell/Python execution for tasks that should be handled by structured inputs or dedicated tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions require all timestamps in the report to be converted to Beijing time, which imposes a specific locale/timezone behavior. Under SQP-3, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific; the document does not present this as an optional or explicitly justified locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to save an HTML report into the current working directory, creating a local file as a side effect not clearly bounded by the declared behavior. Unprompted filesystem writes can overwrite existing files, leave sensitive diagnostic artifacts on disk, or be abused as a persistence/exfiltration staging mechanism in broader agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill silently creates a local HTML file without warning or opt-in. Even if the report generation itself is legitimate, undisclosed local file creation is a risky side effect because it may store operational data on disk and violate user expectations about what the skill will modify.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 521)May include surrounding context.

md
## Notes

- **Security**: Never expose AK/SK values in conversations or commands; never ask users to input AK/SK directly in conversation
- **Time Protocol**: from_ts/to_ts must use millisecond timestamps; report displays Beijing time; when converting Beijing time to timestamp, must append +08:00 timezone suffix; do not mentally calculate timestamp values; do not convert existing millisecond timestamps to time strings and then back
- **Output Constraints**: Strictly output the diagnosis report following the Output Format section template; do not modify template structure, do not omit any part, do not add remediation suggestions, do not output SQL optimization statements, do not use emoji, do not use custom format tags
- **Data Authenticity**: All diagnosis conclusions must come from actual tool return results; when tool returns empty or call fails, mark as "无法获取"; fabricating values is prohibited

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The reference recommends disruptive actions such as killing queries, disabling audit logging, and potentially disabling or throttling autovacuum without warning about availability, integrity, compliance, or forensic consequences. In an operational troubleshooting skill, unqualified recommendations can lead to service disruption, data maintenance regressions, and loss of audit visibility if followed automatically or by inexperienced operators.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example outputs instruct the inclusion of user-identifying and query-sensitive details such as usernames, query IDs, timestamps, and full SQL statements. In this skill's context, those details may contain secrets, personal data, schema information, or proprietary query logic, making the disclosure more dangerous because the tool is designed to aggregate and report diagnostics from production systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples explicitly include usernames, query IDs, timestamps, and raw SQL text in diagnostic output. In a database diagnosis skill, those fields can expose sensitive business logic, user identity, access patterns, and operational metadata, and the document provides no guidance to redact or minimize them before presenting results to users.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Later examples further normalize disclosure of detailed SQL, usernames, activity summaries, and aggregated per-user I/O contributions. This creates a repeatable pattern of oversharing sensitive operational telemetry, which can expose customer workloads, tenant identities, and business processes, especially harmful in a cloud DWS diagnostic skill operating against live clusters.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 27)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 36)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 45)May include surrounding context.

curl -O https://obs-community-tool.obs.cn-north-1.myhuaweicloud.com/hcloudcli/latest/hcloudcli-macos-amd64.tar.gz tar -xzf hcloudcli-macos-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (x86_64)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The section titled "Ruby User Constraint" uses the term "Ruby user" to refer to a specific username that must not appear in output. This creates a natural-language policy issue because it hard-codes a specific language/script representation for a user identifier without any user choice or explanation of locale requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation guide instructs users to place AK/SK secrets in plaintext in a YAML file and states they are only auto-encrypted later on startup. This creates a window where credentials exist unprotected on disk and may be exposed through backups, editor swap files, version control, or accidental sharing, especially in an operations workflow centered on cloud access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dws-mcp-installation-guide.md (reported line 99)May include surrounding context.

Other Commands

bash
# Manually trigger encryption (auto-executed on MCP Server startup as well)
python -m dws_autopilot_mcp.config_cli encrypt

# Show config status (secrets are masked as ******)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML template hard-codes lang="zh-CN", which enforces a specific language/locale in the generated output. The file does not offer any user language choice or explain that this skill is intentionally restricted to a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Several example outputs switch to Chinese labels and descriptions while the rest of the file is in English. This can impose a language/locale choice on users without opt-in, which matches the language-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.