Back to skill

Security audit

huawei-cloud-ecs-shutdown-experiment

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Huawei Cloud ECS shutdown experiment tool with real downtime risk, but its sensitive actions are purpose-aligned and guarded by confirmation, dry-run, validation, and rollback workflows.

Install only if you intentionally need to run controlled ECS shutdown experiments. Use least-privilege, resource-scoped Huawei Cloud credentials; run dry-runs first; confirm target instance IDs and maintenance windows; keep rollback access ready; and avoid the /etc/hosts workaround unless an administrator explicitly approves and verifies rollback.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a broad, end-to-end chaos engineering skill with three phases: prepare, execute, and analyze. The actual code chunk is a single script, analyze_logs.py, whose primary purpose is post-hoc or real-time analysis of an ECS shutdown experiment. It reads experiment metadata from execution-log.json or experiment.json, optionally collects CES metrics and LTS logs, applies regex-based error pattern analysis, and outputs a report. While this behavior aligns with the Phase 3 analysis part of the description, it does not implement the major prepare and execute capabilities that are central to the declared purpose. There is no ECS shutdown/start control path, no experiment preparation logic, no mandatory confirmation, and no rollback script generation/execution in this chunk. Therefore the description materially overstates what this supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a complete chaos engineering workflow for Huawei Cloud ECS shutdown experiments across prepare, execute, and analyze phases. However, the actual code chunk only performs prerequisite environment checks and does not interact with ECS instances, invoke shutdown/start APIs, collect monitoring or logs, or implement the stated safety mechanisms. While an environment check could be a supporting component of the broader skill, this specific supplied code chunk does not accurately represent the described primary behavior and capabilities, so the description and behavior materially mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad, end-to-end chaos engineering workflow centered on ECS shutdown experiments: prepare targets, execute shutdown via BatchStopServers, hold and rollback via BatchStartServers, verify recovery, and analyze impact using CES metrics and LTS logs with safety features like mandatory confirmation and emergency rollback. The supplied code chunk does not implement those core behaviors. Instead, it is narrowly focused on post hoc observability support: querying LTS logs, validating the LTS log collection pipeline, and retrieving ECS endpoint metadata. There are no calls or logic for stopping/starting ECS instances, no experiment lifecycle orchestration, no rollback script generation, no CES metric collection, and no confirmation/approval safety mechanisms. While LTS log collection is a subset of the declared analysis phase, the primary purpose and actual capabilities of this chunk are materially different from the declared full-lifecycle shutdown experiment skill. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive chaos engineering skill for ECS shutdown experiments across preparation, execution, and analysis phases. The supplied code chunk is much narrower: it is a deploy/prep helper that reads local configuration and generates a rollback_experiment.sh script for emergency recovery. The script even states that the experiment has NOT been started and that execution should be done via a separate workflow. Because the actual behavior lacks most of the declared core capabilities—especially shutdown execution and post-analysis—the description materially overstates what this code chunk does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive chaos engineering skill that prepares, executes, and analyzes an ECS shutdown experiment against Huawei Cloud resources. In contrast, the supplied code is a narrowly scoped offline report generator. It consumes an already-prepared JSON file, formats fields into Markdown, and writes the report locally. The docstring explicitly states that no network calls are made, and the implementation confirms that it only uses local file I/O plus formatting logic. While the generated report references experiment, CES, and LTS concepts, the script does not itself perform any experiment actions or data collection. Therefore the code chunk materially under-implements and differs from the declared purpose, indicating a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description represents a comprehensive chaos engineering skill with three phases: preparation, execution, and analysis. In contrast, the supplied code chunk is narrowly scoped to preparation only, specifically generating a configuration directory with experiment.json and README.md. Although the generated README text references a broader execution workflow, those capabilities are not implemented here. The code performs no network/API calls, no ECS instance discovery, no shutdown/start execution, no status polling, no rollback automation, no CES/LTS data collection, and no analysis of logs or metrics. Therefore the description materially overstates the actual behavior of this code chunk, making it a mismatch.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

The document instructs users to download and run a one-click installation script fetched from the internet, which is a classic supply-chain risk because the script executes with local privileges before its contents are independently verified. If the upstream page, download path, or delivery channel were compromised, users of this skill could execute arbitrary code on their systems.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 14)May include surrounding context.

md
KooCLI provides an official one-click installation script that automatically
detects the platform architecture and installs the `hcloud` binary to
`/usr/local/bin/`. Download and run the script from the
[KooCLI installation page](https://support.huaweicloud.com/developer-hcli/hcli_02_0001.html).

For manual installation, download the tar.gz package matching your OS and

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill describes and invokes shell scripts, Python scripts, environment-variable based credentials, and file generation, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this can cause overbroad execution capability, making it easier for the skill to read secrets from the environment, write arbitrary files, or run shell commands beyond what a user expects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow explicitly recommends altering /etc/hosts and pinning a CES endpoint IP obtained via DNS-over-HTTPS to bypass reachability issues. That introduces a system-level network override unrelated to ordinary log analysis, can redirect future CES traffic incorrectly, and may weaken trust in DNS/TLS assumptions if the pinned mapping becomes stale or is manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions recommend modifying /etc/hosts without any warning that this is a privileged, system-wide networking change. In a skill that otherwise performs analysis, this expands behavior into host reconfiguration and could break name resolution, persist beyond the experiment, or misroute traffic if the service IP changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide tells users to export long-lived AK/SK credentials into environment variables without warning that these secrets can be exposed through shell history, process inspection, debug output, crash reports, or inherited subprocess environments. In a chaos-engineering skill that performs destructive ECS stop/start operations, exposed credentials could let an attacker control cloud resources well beyond the intended experiment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This guide documents a shutdown fault-injection template but does not prominently warn readers that the experiment intentionally stops ECS instances and may cause service interruption, downtime, or data loss if used on production systems. In a chaos-engineering skill that operationalizes prepare/execute/analyze phases, omission of a clear user-facing impact warning increases the chance of accidental disruptive use by operators who rely on the template as authoritative guidance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to alter /etc/hosts to override DNS resolution for a cloud service endpoint. Modifying local name resolution changes system networking behavior beyond the experiment itself, requires elevated privileges, and can misroute future traffic if not reverted or if the pinned public IP changes. In the context of an ECS shutdown experiment, this is ancillary troubleshooting guidance rather than an essential experiment step, so it meaningfully expands operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell the user to back up and append to /etc/hosts without an explicit warning that this changes system-wide networking behavior and typically needs elevated privileges. Even though a restore command is shown, the guidance normalizes privileged local system modification in a troubleshooting section, which can cause persistent connectivity issues or incorrect trust in a manually pinned endpoint. Because the skill is for chaos engineering on cloud resources, adding undocumented host-level changes makes the operational blast radius broader than expected.

Content

No source excerpt is available for this finding.

Tainted flow: 'env' from os.environ.get (line 45, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/collect_logs.py (reported line 88)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_env(region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=120
        )
        if result.returncode != 0:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/execute_experiment.py (reported line 433)May include surrounding context.

python
with open(log_path, "w") as f:
        f.write(log_json)
    if log.get("overall_result") == "refused_no_confirmation":
        print("Execution refused: no confirmation given (--yes).")
        sys.exit(1)
    print(f"Execution log written to: {log_path}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/collect_logs.py (reported line 88)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_subprocess_env(region=region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=120
        )
        if result.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/execute_experiment.py (reported line 41)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_subprocess_env(region=region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=120
        )
        if result.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/rollback_experiment.py (reported line 34)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_subprocess_env(region=region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=120
        )
        if result.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/discover_ecs.py (reported line 48)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_env(region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=60
        )
        if result.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/monitor_instances.py (reported line 61)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_env(region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=60
        )
        if result.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/validate_targets.py (reported line 48)May include surrounding context.

python
cmd.append(f"--cli-region={region}")
    env = _build_env(region)
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, env=env, timeout=60
        )
        if result.returncode != 0:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Multiple command examples fix the region to cn-north-4, and the network error example includes Chinese-language output, which suggests a specific locale/region assumption. The document does not clearly state that the skill is region-specific or let the user choose another region.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.