Back to skill

Security audit

huawei-cloud-ecs-dsh-deploy

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned for deploying dsh, but it needs review because its actual network setup contradicts its SSH-only access claims and may expose the web UI to cloud-network peers.

Review before installing. Use temporary least-privilege Huawei credentials, avoid --auto-confirm and --force-delete unless you fully understand the impact, expect real cloud charges, and verify the security group after deployment. Do not rely on the documentation’s empty-security-group claim unless the code is fixed to remove the self-referencing ingress rules and bind/remove nginx according to the intended SSH-only model.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/deploy_dsh.py:54
Finding

Security-group peers can bypass the SSH tunnel and access the dsh Web UI

Content
View full analysis

Vulnerability Details

File Location: scripts/deploy_dsh.py:54-65; scripts/coc_deploy.py:218-244; scripts/coc_deploy.py:252-259
Vulnerability Type: Network access-control bypass caused by a self-referencing security-group rule and an externally listening reverse proxy
Risk Level: High

Vulnerable Code

python
# scripts/deploy_dsh.py:54-65
if existing_sg:
    sg_id = existing_sg.get("id")
    print(f"✅ Using existing security group: {sg_name} ({sg_id})")
    return sg_id

sg_id = client.create_security_group(sg_name, vpc_id)
if not sg_id:
    print("❌ Failed to create security group")
    return None

client.add_security_group_rule(
    sg_id,
    remote_group_id=sg_id,
    description="Allow all IPv4 traffic within security group"
)
client.add_security_group_rule(
    sg_id,
    ip_version="IPv6",
    remote_group_id=sg_id,
    description="Allow all IPv6 traffic within security group"
)
nginx
# scripts/coc_deploy.py:218-244
cat > /etc/nginx/conf.d/dsh.conf << 'NGINXEOF'
server {
    listen 80;
    server_name _;
    client_max_body_size 50M;

    location / {
        proxy_pass http://127.0.0.1:%%DSH_PORT%%;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_read_timeout 3600s;
        proxy_send_timeout 3600s;
    }
}
NGINXEOF
bash
# scripts/coc_deploy.py:252-259
if command -v ufw > /dev/null 2>&1; then
    ufw allow 22/tcp > /dev/null 2>&1 || true
    ufw allow 80/tcp > /dev/null 2>&1 || true
    ufw allow 443/tcp > /dev/null 2>&1 || true
    echo "[$(date)] UFW: allowed 22/80/443"
else
    echo "[$(date)] No UFW found; ensure cloud security group opens ports 22/80/443"
fi

Technical Analysis

The deployment claims t ...[truncated 2823 chars]

Remediation
View remediation

Remediation Suggestions

  1. Bind the reverse proxy to loopback explicitly:
nginx
listen 127.0.0.1:80;
listen [::1]:80;
  1. Remove the UFW allowances for ports 80 and 443 when access is intended exclusively through an SSH tunnel:
bash
ufw delete allow 80/tcp
ufw delete allow 443/tcp
  1. Do not create unrestricted self-referencing ingress rules. If peer communication is genuinely required, restrict it to the exact protocol and port needed. For this deployment, no peer ingress rule is necessary for the SSH-tunnel design.

  2. Create a unique security group per deployment, or validate every rule before reusing sg-dsh. Do not rely only on the group name.

  3. Fail deployment if the selected security group contains ingress rules broader than the documented policy.

  4. Add an automated post-deployment check that attempts to connect to ports 80 and 3080 through the instance's private interface and fails the deployment if either is reachable.

  5. If private-network Web UI access is intentionally supported, document it explicitly and add application-layer authentication rather than representing the service as SSH-tunnel-only.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (83)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior and declared purpose do not fully match the skill's described capabilities: it supports remote operations on existing instances, stores a DEEPSEEK_API_KEY on the target host, and includes status/delete style lifecycle actions beyond simple deployment. Behavior mismatches are dangerous because they undermine informed consent and can lead users or agents to authorize credential handling, remote execution, or cloud changes they did not expect.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 257)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
| **List Regions** | Show available regions | `python3 scripts/deploy_dsh.py --list-regions` |

Static analysis

No suspicious patterns detected.