Security checks for vulnerabilities and agentic risk
Overview
This skill mostly matches its Huawei Cloud monitoring purpose, but it can make cloud changes and delete notification subscriptions without an enforced confirmation gate.
Review this skill before installing if it will run against production Huawei Cloud credentials. Use a least-privilege IAM policy instead of broad FullAccess where possible, require manual review before any create/update/delete script is run, do not paste AK/SK into chat or command history, and be especially careful with SMN subscription deletion because it can interrupt alarm notifications.
Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T09 · Insecure Skill Coding Practices
Warning
Location
scripts/manage_notifications.sh:138
Finding
SMN Subscription Deletion Does Not Enforce User Confirmation
Content
View full analysis
Vulnerability Details
File Location: scripts/manage_notifications.sh, lines 138–151 Vulnerability Type: Destructive cloud operation without an enforced confirmation gate Risk Level: Medium
Vulnerable Code
bash
delete)
if [[ -z "$SUBSCRIPTION_URN" ]]; then
echo "Error: For delete action, --subscription-urn is required" >&2
exit 1
fi
echo "Deleting SMN subscription..." >&2
echo " Subscription URN: $SUBSCRIPTION_URN" >&2
echo " Region: $REGION" >&2
echo "" >&2
if hcloud SMN BatchDeleteSubscriptions \
--cli-region="$REGION" \
--subscription_urns.1.subscription_urn="$SUBSCRIPTION_URN" 2>&1; then
Technical Analysis
The script immediately invokes Huawei Cloud’s authenticated BatchDeleteSubscriptions operation after checking only that a subscription URN was supplied. It does not require an interactive confirmation, a confirmation token tied to the exact URN, or a dry-run mode.
Merely printing the selected subscription does not establish user consent. This contradicts the explicit confirmation boundary documented in:
SKILL.md:93, which requires confirmation before creating or deleting subscriptions.
SKILL.md:124–131, which identifies subscription deletion as a write operation requiring confirmation.
SKILL.md:286–298, which requires all create, update, and delete operations to display their content and obtain explicit user confirmation.
references/acceptance-criteria.md:45–51, which requires deletion to prompt for confirmation.
Because the executable entry point does not enforce that policy, an Agent or automation workflow can call it directly and bypass the documented safeguard.
Attack Path
Huawei Cloud credentials with SMN deletion privileges are configured for hcloud.
An Agent, automation workflow, or other local caller invokes:
bash
Require interactive confirmation before deletion, displaying the exact subscription URN and region.
Refuse destructive operations when standard input is not an interactive terminal unless an explicit non-interactive confirmation mechanism is supplied.
For automation, require a value bound to the target, such as:
bash
--confirm-delete '<exact-subscription-URN>'
Verify that it exactly matches --subscription-urn.
Add a default dry-run mode that prints the intended operation without invoking Huawei Cloud.
Consider querying and displaying subscription metadata before approval so the user can verify the endpoint and topic.
Add tests proving that deletion cannot reach BatchDeleteSubscriptions without explicit confirmation.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Content
No source excerpt is available for this finding.
Tp4
High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared description focuses on CES alarm rule lifecycle management for ECS instances: batch alarm creation, notification updates, and querying metrics/alarms. The actual code does none of those core tasks. Instead, it creates an SMN email subscription on a topic, which is a separate notification setup action. While SMN can support alarm notifications, this script’s primary purpose is not alarm rule management and the described triggers like 'create alert', 'list alarms', or 'CPU alert' do not accurately match this code chunk’s behavior.
Content
No source excerpt is available for this finding.
Tp4
High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a clear description-behavior mismatch. The declared purpose centers on CES alarm rule lifecycle management for ECS instances, including batch creation, notification updates, and alarm/metric queries. The actual code only retrieves ECS instance details from the ECS service (ListServersDetails) and formats the results. While ECS instances are related to the broader cloud environment, the script's primary purpose is inventory/listing of compute instances, not monitoring/alarm management. Therefore the code accesses a different resource domain and lacks the core declared capabilities.
Content
No source excerpt is available for this finding.
Tp4
High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This code chunk’s behavior is centered on SMN discovery/listing, not CES alarm management. While SMN can be related to alarm notifications, the script is read-only and limited to listing topics/subscriptions in a region. The declared purpose emphasizes batch alarm creation/management for ECS instances, notification updates, and ECS/alarm queries. Those core capabilities are absent, making this a material description-to-behavior mismatch.
Content
No source excerpt is available for this finding.
Ae1
High
Category
analysis-evasion
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected
Content
Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.
md
5. **Use Environment Check Script**: Run `./scripts/check_env.sh` before first use to verify configuration
Tool Parameter Abuse
High
Category
Tool Misuse
Confidence
80% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Content
Scanner excerpt · references/related-apis.md (reported line 167)May include surrounding context.
md
**Function**: Unsubscribe endpoint(s) from topic
**API**: `DELETE /v2/{project_id}/notifications/topics/{topic_urn}/subscriptions`
**hcloud Command**:
Undeclared Tool Scope
Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill documents shell-script execution and use of environment-derived configuration but does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization gap where an agent may invoke shell or read environment data more broadly than users expect, increasing the chance of unintended command execution or secret exposure.
Content
No source excerpt is available for this finding.
Shadow Command Trigger
Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding
The trigger phrase 'create alert' is generic and overlaps with common built-in 'create' workflows. Such shadowing can cause the wrong skill to activate for unrelated requests, which is more dangerous here because the skill exposes shell-backed write operations against cloud resources.
Content
No source excerpt is available for this finding.
Shadow Command Trigger
Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding
The trigger 'list alarms' is also generic and may intercept ordinary listing requests intended for another tool or product. In a skill that can enumerate cloud resources and lead into write workflows, command shadowing increases the risk of unintended activation and information disclosure.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding
Several triggers such as 'create alert', 'list alarms', and generic monitoring phrases are broad enough to match unrelated user requests. In an agent environment, overly broad activation can route requests into a shell-capable cloud-management skill unexpectedly, increasing the risk of unintended infrastructure actions or disclosure of cloud inventory.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding
The skill gives contradictory credential guidance: one section says AK/SK should use environment variables or hcloud configure, while later sections state hcloud ignores AK/SK environment variables. Conflicting authentication instructions are dangerous because users may misconfigure access, fall back to insecure practices, or expose credentials via command-line arguments after failed attempts.
Content
No source excerpt is available for this finding.
Autonomous Decision Making
Medium
Category
Excessive Agency
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Content
Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.
Core Commands
Query Commands (read-only, no confirmation needed)
bash
# List ECS instances
Session Persistence
Medium
Category
Rogue Agent
Confidence
60% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Content
Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.
The manifest positions the skill as focused on ECS CES alarm rule creation, notification updates, and queries, and explicitly emphasizes prohibition of delete alarm operations. However, the documented capabilities and workflows include delete operations for SMN subscriptions, which extends behavior beyond the narrowly stated create/update/query framing in the manifest description. While related to notifications, deletion is still a destructive management action not reflected in the top-level manifest summary.
Content
No source excerpt is available for this finding.
Session Persistence
Medium
Category
Rogue Agent
Confidence
60% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Content
Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.
md
> ./scripts/list_alarms.sh --name "cpu.*" # Filter by name pattern
> ./scripts/list_alarms.sh --format ids # Output only alarm IDs
>
> # Create alarm rules
>
> ./scripts/create_alert_rules.sh --template web --ecs-ids ecs-001,ecs-002
> ./scripts/create_alert_rules.sh --metric cpu_util --threshold 80 --ecs-ids ecs-001
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
Line L099 says the skill triggers on "ECS alert", "create alert", "monitoring alert" etc., which does not provide a bounded trigger list and includes phrases broad enough to overlap with ordinary requests about alerts. The trailing "etc." makes activation scope unclear and gives no negative examples or exclusion conditions.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding
The documentation grants SMN FullAccess and explicitly states the ability to create and manage SMN topics, subscribe/unsubscribe endpoints, and send notifications, which exceeds the skill’s stated need to update alarm notifications for ECS alarms. This violates least-privilege and could enable unnecessary modification of notification infrastructure if the credential used with the skill is compromised or the operator follows the documentation as written.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The troubleshooting guide instructs users to pass AK/SK credentials directly on the command line, which can expose secrets through shell history, process listings, terminal scrollback, logging systems, or CI job output. In the context of a cloud administration skill, these credentials likely grant access to production monitoring and notification resources, so disclosure could enable unauthorized cloud actions.
Content
No source excerpt is available for this finding.
subprocess module call
Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
Content
Scanner excerpt · scripts/config.py (reported line 45)May include surrounding context.
python
# 3. If still not set, try reading from hcloud CLI config
if not ak or not sk:
try:
result = subprocess.run(
["hcloud", "configure", "list"],
capture_output=True,
text=True,
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The manifest describes a skill for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying metrics/alarms. This script instead provisions a new SMN email subscription via hcloud SMN AddSubscription, which manages notification endpoints/topics directly rather than alarm rules or alarm-list querying.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The manifest says this skill is for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying ECS metrics and alarm lists. This script instead lists ECS instances via hcloud ECS ListServersDetails, which is a separate inventory capability not described in the manifest's purpose or supported use cases.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding
Calling hcloud ECS ListServersDetails retrieves full ECS server details, including names, statuses, flavors, and IP addresses. For a skill whose declared purpose is CES alarm creation/management and querying metrics/alarm lists, general-purpose enumeration of ECS instances is an additional capability that is not explicitly justified by the manifest.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding
The manifest describes a skill for batch creation and management of Huawei Cloud CES alarm rules for ECS instances, including updating SMN notifications and querying ECS metrics/alarm lists. This script instead enumerates SMN topics and subscriptions directly, which is adjacent infrastructure discovery rather than ECS alarm-rule creation, notification update, or alarm/metric querying as described.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding
The code provides a standalone capability to list all SMN topics and all subscriptions in a region. While SMN notifications are related to alarms, broad inventory listing of messaging resources is a separate capability not clearly required by the manifest’s stated functions of creating ECS alarms, updating notifications, and querying ECS metrics/alarm lists.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Low
Category
Not specified by scanner
Confidence
80% confidence
Finding
The document first says the skill must be granted 'SMN FullAccess' as a minimum requirement, but the later custom policy example only includes SMN list/subscribe/unsubscribe actions. This creates intent ambiguity in the documentation about whether full administrative SMN access is truly required.
Content
No source excerpt is available for this finding.
Static analysis
Detected: suspicious.exposed_secret_literal
File appears to expose a hardcoded API secret or token.