Back to skill

Security audit

huawei-cloud-ecs-alert

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its Huawei Cloud monitoring purpose, but it can make cloud changes and delete notification subscriptions without an enforced confirmation gate.

Review this skill before installing if it will run against production Huawei Cloud credentials. Use a least-privilege IAM policy instead of broad FullAccess where possible, require manual review before any create/update/delete script is run, do not paste AK/SK into chat or command history, and be especially careful with SMN subscription deletion because it can interrupt alarm notifications.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/manage_notifications.sh:138
Finding

SMN Subscription Deletion Does Not Enforce User Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/manage_notifications.sh, lines 138–151
Vulnerability Type: Destructive cloud operation without an enforced confirmation gate
Risk Level: Medium

Vulnerable Code

bash
delete)
    if [[ -z "$SUBSCRIPTION_URN" ]]; then
        echo "Error: For delete action, --subscription-urn is required" >&2
        exit 1
    fi

    echo "Deleting SMN subscription..." >&2
    echo "  Subscription URN: $SUBSCRIPTION_URN" >&2
    echo "  Region: $REGION" >&2
    echo "" >&2

    if hcloud SMN BatchDeleteSubscriptions \
        --cli-region="$REGION" \
        --subscription_urns.1.subscription_urn="$SUBSCRIPTION_URN" 2>&1; then

Technical Analysis

The script immediately invokes Huawei Cloud’s authenticated BatchDeleteSubscriptions operation after checking only that a subscription URN was supplied. It does not require an interactive confirmation, a confirmation token tied to the exact URN, or a dry-run mode.

Merely printing the selected subscription does not establish user consent. This contradicts the explicit confirmation boundary documented in:

  • SKILL.md:93, which requires confirmation before creating or deleting subscriptions.
  • SKILL.md:124–131, which identifies subscription deletion as a write operation requiring confirmation.
  • SKILL.md:286–298, which requires all create, update, and delete operations to display their content and obtain explicit user confirmation.
  • references/acceptance-criteria.md:45–51, which requires deletion to prompt for confirmation.

Because the executable entry point does not enforce that policy, an Agent or automation workflow can call it directly and bypass the documented safeguard.

Attack Path

  1. Huawei Cloud credentials with SMN deletion privileges are configured for hcloud.
  2. An Agent, automation workflow, or other local caller invokes:
    bash
    ./scripts/manage_notifications.sh \
      --action delete \
      --subscription-urn '<target-su
    

...[truncated 860 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require interactive confirmation before deletion, displaying the exact subscription URN and region.
  2. Refuse destructive operations when standard input is not an interactive terminal unless an explicit non-interactive confirmation mechanism is supplied.
  3. For automation, require a value bound to the target, such as:
    bash
    --confirm-delete '<exact-subscription-URN>'
    
    Verify that it exactly matches --subscription-urn.
  4. Add a default dry-run mode that prints the intended operation without invoking Huawei Cloud.
  5. Consider querying and displaying subscription metadata before approval so the user can verify the endpoint and topic.
  6. Add tests proving that deletion cannot reach BatchDeleteSubscriptions without explicit confirmation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description focuses on CES alarm rule lifecycle management for ECS instances: batch alarm creation, notification updates, and querying metrics/alarms. The actual code does none of those core tasks. Instead, it creates an SMN email subscription on a topic, which is a separate notification setup action. While SMN can support alarm notifications, this script’s primary purpose is not alarm rule management and the described triggers like 'create alert', 'list alarms', or 'CPU alert' do not accurately match this code chunk’s behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose centers on CES alarm rule lifecycle management for ECS instances, including batch creation, notification updates, and alarm/metric queries. The actual code only retrieves ECS instance details from the ECS service (ListServersDetails) and formats the results. While ECS instances are related to the broader cloud environment, the script's primary purpose is inventory/listing of compute instances, not monitoring/alarm management. Therefore the code accesses a different resource domain and lacks the core declared capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk’s behavior is centered on SMN discovery/listing, not CES alarm management. While SMN can be related to alarm notifications, the script is read-only and limited to listing topics/subscriptions in a region. The declared purpose emphasizes batch alarm creation/management for ECS instances, notification updates, and ECS/alarm queries. Those core capabilities are absent, making this a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
5. **Use Environment Check Script**: Run `./scripts/check_env.sh` before first use to verify configuration

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/related-apis.md (reported line 167)May include surrounding context.

md
**Function**: Unsubscribe endpoint(s) from topic

**API**: `DELETE /v2/{project_id}/notifications/topics/{topic_urn}/subscriptions`

**hcloud Command**:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents shell-script execution and use of environment-derived configuration but does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization gap where an agent may invoke shell or read environment data more broadly than users expect, increasing the chance of unintended command execution or secret exposure.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding

The trigger phrase 'create alert' is generic and overlaps with common built-in 'create' workflows. Such shadowing can cause the wrong skill to activate for unrelated requests, which is more dangerous here because the skill exposes shell-backed write operations against cloud resources.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding

The trigger 'list alarms' is also generic and may intercept ordinary listing requests intended for another tool or product. In a skill that can enumerate cloud resources and lead into write workflows, command shadowing increases the risk of unintended activation and information disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several triggers such as 'create alert', 'list alarms', and generic monitoring phrases are broad enough to match unrelated user requests. In an agent environment, overly broad activation can route requests into a shell-capable cloud-management skill unexpectedly, increasing the risk of unintended infrastructure actions or disclosure of cloud inventory.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill gives contradictory credential guidance: one section says AK/SK should use environment variables or hcloud configure, while later sections state hcloud ignores AK/SK environment variables. Conflicting authentication instructions are dangerous because users may misconfigure access, fall back to insecure practices, or expose credentials via command-line arguments after failed attempts.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

Core Commands

Query Commands (read-only, no confirmation needed)

bash
# List ECS instances

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

./scripts/batch_query_metrics.sh --ecs-ids --metric cpu_util --period 1h

text

### Create Commands (write operations, require user confirmation)

```bash
# Batch create alarm rules (WARNING: confirm target ECS and alarm template)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest positions the skill as focused on ECS CES alarm rule creation, notification updates, and queries, and explicitly emphasizes prohibition of delete alarm operations. However, the documented capabilities and workflows include delete operations for SMN subscriptions, which extends behavior beyond the narrowly stated create/update/query framing in the manifest description. While related to notifications, deletion is still a destructive management action not reflected in the top-level manifest summary.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
> ./scripts/list_alarms.sh --name "cpu.*"  # Filter by name pattern
> ./scripts/list_alarms.sh --format ids          # Output only alarm IDs
> 
> # Create alarm rules
> 
> ./scripts/create_alert_rules.sh --template web --ecs-ids ecs-001,ecs-002
> ./scripts/create_alert_rules.sh --metric cpu_util --threshold 80 --ecs-ids ecs-001

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L099 says the skill triggers on "ECS alert", "create alert", "monitoring alert" etc., which does not provide a bounded trigger list and includes phrases broad enough to overlap with ordinary requests about alerts. The trailing "etc." makes activation scope unclear and gives no negative examples or exclusion conditions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation grants SMN FullAccess and explicitly states the ability to create and manage SMN topics, subscribe/unsubscribe endpoints, and send notifications, which exceeds the skill’s stated need to update alarm notifications for ECS alarms. This violates least-privilege and could enable unnecessary modification of notification infrastructure if the credential used with the skill is compromised or the operator follows the documentation as written.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting guide instructs users to pass AK/SK credentials directly on the command line, which can expose secrets through shell history, process listings, terminal scrollback, logging systems, or CI job output. In the context of a cloud administration skill, these credentials likely grant access to production monitoring and notification resources, so disclosure could enable unauthorized cloud actions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/config.py (reported line 45)May include surrounding context.

python
# 3. If still not set, try reading from hcloud CLI config
    if not ak or not sk:
        try:
            result = subprocess.run(
                ["hcloud", "configure", "list"],
                capture_output=True,
                text=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying metrics/alarms. This script instead provisions a new SMN email subscription via hcloud SMN AddSubscription, which manages notification endpoints/topics directly rather than alarm rules or alarm-list querying.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill is for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying ECS metrics and alarm lists. This script instead lists ECS instances via hcloud ECS ListServersDetails, which is a separate inventory capability not described in the manifest's purpose or supported use cases.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Calling hcloud ECS ListServersDetails retrieves full ECS server details, including names, statuses, flavors, and IP addresses. For a skill whose declared purpose is CES alarm creation/management and querying metrics/alarm lists, general-purpose enumeration of ECS instances is an additional capability that is not explicitly justified by the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying ECS metrics/alarm lists. This script instead enumerates SMN topics and subscriptions directly, which is adjacent infrastructure discovery rather than ECS alarm-rule creation, notification update, or alarm/metric querying as described.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code provides a standalone capability to list all SMN topics and all subscriptions in a region. While SMN notifications are related to alarms, broad inventory listing of messaging resources is a separate capability not clearly required by the manifest’s stated functions of creating ECS alarms, updating notifications, and querying ECS metrics/alarm lists.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document first says the skill must be granted 'SMN FullAccess' as a minimum requirement, but the later custom policy example only includes SMN list/subscribe/unsubscribe actions. This creates intent ambiguity in the documentation about whether full administrative SMN access is truly required.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/common-commands.md:76