Back to skill

Security audit

huawei-cloud-ecs-sqlbot-deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill is aimed at deploying SQLBot on Huawei Cloud, but it can create billable cloud resources without an enforceable approval step and handles credentials/passwords in unsafe ways.

Review carefully before installing. Use only short-lived, least-privilege Huawei credentials, do not paste real AK/SK into chat or shell history, require a manual dry run or code change before any resource creation, remove shared default passwords, disable password notifications, and avoid running the remote installer path without verifying its contents.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/deploy_sqlbot.py:244
Finding

Deployment Entry Point Creates Billable Cloud Resources Without Enforcing User Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/deploy_sqlbot.py:244-249, 261-363
Vulnerability Type: Missing authorization and confirmation gate for destructive or billable operations
Risk Level: High

Code Snippet

python
# Simple confirmation (optional, can be commented out)
# confirm = input("\nContinue creating server? (y/N): ")
# if confirm.lower() != 'y':
#     print("Creation cancelled")
#     return

The execution then proceeds directly to resource creation:

python
existing_sg = client.get_security_group_by_name(sg_name)
if existing_sg:
    sg_id = existing_sg.get("id")
    print(f"✅ Using existing security group: {sg_name} ({sg_id})")
else:
    sg_id = client.create_security_group(sg_name, network.get("vpc_id"))

if sg_id:
    print(f"\n🔐 Adding port access rules...")

    client.add_security_group_rule(
        sg_id,
        port_range_min=8000,
        port_range_max=8000,
        remote_ip_prefix="192.168.0.0/16",
        description="SQLBot Web port"
    )

Billable server creation subsequently occurs without another confirmation check:

python
if charging_mode == "prePaid":
    result = client.create_prepaid_server_with_sdk(
        server_name=args.name,
        flavor_id=flavor_id,
        image_id=image_id,
        volume_size=args.volume_size,
        vpc_id=network.get("vpc_id"),
        subnet_id=network.get("subnet_id"),
        security_group_id=sg_id,
        admin_pass=args.password,
        availability_zone=zone,
        eip_bandwidth=args.bandwidth,
    )
else:
    result = client.create_postpaid_server_with_sdk(
        server_name=args.name,
        flavor_id=flavor_id,
        image_id=image_id,
        volume_size=args.volume_size,
        vpc_id=network.get("vpc_id"),
        subnet_id=network.get("subnet_id"),
        security_group_id=sg_id,
        admin_pass=args.password,
        availability_zone=zone,
        eip_bandwidth=args.bandwidth,
    )

Technical Analysis

SKILL.md ...[truncated 2112 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default the program to a non-mutating dry-run that only resolves and displays the final configuration.
  2. Require an explicit approval immediately before the first mutating cloud API request.
  3. For interactive use, require a clear affirmative response and fail closed on EOF, timeout, or any unrecognized response.
  4. For non-interactive use, require a dedicated parameter such as --approve-config-digest SHA256, where the digest is calculated from the exact displayed region, billing mode, flavor, disk, EIP, network, and server name.
  5. Require a new approval whenever any deployment parameter changes.
  6. Implement the documented second confirmation for custom configurations.
  7. Keep confirmation checks in the executable path rather than relying exclusively on Agent instructions.
  8. Separate validation and planning from resource creation so credentials can be tested without triggering mutations.
  9. Add automated tests proving that no mutating API method is called without a valid approval state.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/huawei_cloud_ecs.py:271
Finding

TLS Certificate Verification Is Disabled for Signed Huawei Cloud API Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/huawei_cloud_ecs.py:271-286
Vulnerability Type: Improper certificate validation on authenticated API traffic
Risk Level: High

Code Snippet

python
def _do_request(self, method, url, body=None, timeout=120):
    """Execute signed request"""
    body_str = json.dumps(body, ensure_ascii=False) if body else ""
    request = self._sign_request(method, url, body_str)
    full_url = f"{request.schema}://{request.host}{request.resource_path}"
    
    if method == "GET":
        resp = requests.get(url=full_url, headers=request.header_params, verify=False, timeout=timeout)
    elif method == "POST":
        resp = requests.post(url=full_url, headers=request.header_params, data=body_str, verify=False, timeout=timeout)
    elif method == "PUT":
        resp = requests.put(url=full_url, headers=request.header_params, data=body_str, verify=False, timeout=timeout)
    elif method == "DELETE":
        resp = requests.delete(url=full_url, headers=request.header_params, verify=False, timeout=timeout)
    else:
        raise ValueError(f"Unsupported method: {method}")
        
    return resp

Technical Analysis

Every request made through _do_request disables server-certificate validation with verify=False. This affects signed ECS and VPC API operations, including authentication tests, image discovery, network discovery and creation, security-group management, and server-related operations.

HTTPS encryption without certificate validation does not authenticate the remote endpoint. A network attacker able to intercept traffic or redirect DNS can present an arbitrary certificate and terminate the TLS session.

The requests contain Huawei Cloud signing material in authorization headers and may contain X-Security-Token for temporary credentials. This does not directly disclose the Secret Key, but it exposes signed requests and temporary-token material to the interception point. Eligible signed requ ...[truncated 1879 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove every verify=False argument and use Requests’ default certificate validation.
  2. Remove the global urllib3.disable_warnings() call so certificate failures remain visible.
  3. If a private enterprise CA is necessary, accept an explicit CA-bundle path and pass it as verify="/trusted/path/ca-bundle.pem".
  4. Do not provide a general-purpose option that silently disables verification.
  5. Validate that constructed endpoints use the expected https scheme and approved Huawei Cloud hostname patterns.
  6. Apply normal redirect restrictions to prevent signed headers from being forwarded to unexpected origins.
  7. Rotate temporary credentials if they were used over an untrusted network while certificate verification was disabled.
  8. Add tests using an untrusted test certificate and verify that all cloud API requests fail closed.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:28
Finding

Deployments Use Publicly Known Shared Default Administrative Passwords

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py:28, with use at scripts/huawei_cloud_ecs.py:747,983 and disclosure at scripts/deploy_sqlbot.py:505,524
Vulnerability Type: Hardcoded and predictable administrative credentials
Risk Level: Medium

Code Snippet

The default ECS administrator password is hardcoded:

python
DEFAULT_CONFIG = {
    "flavor": None,
    "image": "Ubuntu 22.04 server 64bit",
    "os_version": "22.04",
    "architecture": "x86_64",
    "availability_zone": None,
    "charging_mode": "postPaid",
    "eip_bandwidth": 300,
    "eip_charge_mode": "traffic",
    "admin_pass": "Test@123456",
    "sqlbot_ports": [8000]
}

Both server-creation paths use that shared password when the caller does not provide one:

python
admin_pass = admin_pass or DEFAULT_CONFIG["admin_pass"]

The deployment output also declares a fixed SQLBot administrator password:

python
print(f"   Username: admin")
print(f"   Password: SQLBot@123456")

The same credential is included in notifications:

python
f"  Username: admin\n"
f"  Password: SQLBot@123456\n\n"

Technical Analysis

The server password falls back to a constant embedded in the package whenever --password is omitted. The documented default invocation does not require that argument, making use of the shared password a reachable default behavior.

The project also treats admin / SQLBot@123456 as the deployed SQLBot login and publishes it in SKILL.md, deployment output, notifications, and acceptance criteria. Therefore, these are not deployment-specific secrets and must be assumed known to any party that can inspect the Skill.

A complex-looking password does not provide meaningful protection when it is identical across deployments and publicly documented. Network restrictions reduce exposure but do not correct the authentication weakness. The deployment explicitly permits SQLBot port 8000 from 192.168.0.0/16, so another compromised or unauthor ...[truncated 1770 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all hardcoded default passwords.
  2. Generate a unique, cryptographically secure password for every deployment using secrets, or require the user to supply a password through an approved secret mechanism.
  3. Enforce the cloud provider’s password complexity and length requirements before resource creation.
  4. Generate a separate random SQLBot administrator secret during installation.
  5. Store generated credentials in an authorized secret manager rather than source files, command output, chat messages, or general notification channels.
  6. Do not print plaintext server or application passwords to stdout.
  7. Do not include passwords in Feishu notification messages.
  8. Require password rotation or account initialization on first SQLBot access.
  9. Prefer short-lived access methods, instance-connect mechanisms, or SSH public keys for server administration.
  10. Document revocation and rotation procedures for deployments created with the old shared passwords.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims automated cloud provisioning and deployment using Huawei SDKs, but the content appears primarily instructional and lacks evidence of actual authenticated API operations and safeguards. Such overclaiming can mislead operators into sharing secrets or approving risky actions under false assumptions about what the skill really does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims automated cloud provisioning and deployment using Huawei SDKs, but the content appears primarily instructional and lacks evidence of actual authenticated API operations and safeguards. Such overclaiming can mislead operators into sharing secrets or approving risky actions under false assumptions about what the skill really does.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Publishing a default admin credential example without a mandatory warning to rotate or disable it encourages operators to leave a known password in place. In this skill's context, the service is intended for one-click internet-accessible deployment, so a default credential can be rapidly discovered and abused for unauthorized access.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 16)May include surrounding context.

md
# If not installed, use package manager
# Ubuntu/Debian
sudo apt update && sudo apt install python3 python3-pip -y

# CentOS/RHEL
sudo yum install python3 python3-pip -y

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code sends newly created server credentials, including the initial instance password, through Feishu notifications. Transmitting privileged credentials over a chat/notification channel materially increases the chance of credential disclosure, account takeover of the instance, and downstream compromise of the deployed application and cloud environment.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly formats and sends the server's initial password in plain language to a Feishu recipient. Plaintext credential disclosure is a high-risk pattern because it defeats least privilege, increases accidental sharing, and allows full administrative access if the message is intercepted or viewed by unintended parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The notification content includes sensitive server credentials and access details without meaningful safeguards, beyond a brief 'keep it secure' note. Sending secrets to a messaging recipient is dangerous because chat recipients, bots, logs, previews, and retention systems may all gain access to credentials outside the intended administrative boundary.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

This notification exposes both infrastructure-level credentials and application-level admin credentials, giving an attacker everything needed to access the VM and the SQLBot service. In context, this is especially dangerous because the tool is internet-facing deployment automation, so disclosed credentials can enable rapid full-environment compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The success notification discloses both the instance password and the SQLBot application credentials, including a default admin password, to the configured messaging recipient. This creates an immediate compromise path because anyone with access to the notification or its retention history can log into the server and application.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares capabilities that imply access to environment variables, filesystem, network, and shell, but it does not constrain tool scope with explicit permissions or allowed-tools. In a deployment skill that handles cloud credentials and creates infrastructure, this broad implicit authority increases the blast radius of prompt injection, misuse, or accidental execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: |
  Purchase Huawei Cloud X Instance server + one-click deploy SQLBot intelligent query application.
  Tech stack: Python 3.8+, Huawei Cloud SDK, COC (Cloud Operations Center) deployment.
  Key capabilities: AK/SK auth, X instance creation, auto security group config, SQLBot auto deployment.
  Use cases: Users who need to quickly deploy SQLBot intelligent query application on Huawei Cloud X instance servers.
  Trigger words: "deploy sqlbot", "install sqlbot", "sqlbot deploy", "one-click deploy sqlbot", "x-instance deploy sqlbot", "部署sqlbot", "安装sqlbot", "sqlbot部署", "一键部署sqlbot", "x实例部署sqlbot".
tags: [huawei-cloud, x-instance, sqlbot, deployment]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes automated purchase/deployment of billable cloud resources and later uses default server and application passwords, but it does not prominently warn users upfront about cost incurrence and the security implications of default credentials. This combination can result in unexpected charges and immediately exploitable exposed systems if deployed as described.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill directs automatic reading of cloud credentials from environment variables without prior user consent. Even if intended for convenience, autonomous secret access is risky because it normalizes silent credential harvesting and can expose or misuse credentials in contexts where the user did not expect them to be touched.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

━━━ STEP 1: Auto-check Credentials (Environment Variables) ━━━

When user triggers the skill, first automatically get credentials from environment variables without asking user:

bash
# Check credentials (prefer temporary credentials)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation first says the skill will never ask users to input AK/SK directly, then later instructs the user to provide AK/SK and Security Token when environment variables are absent. This contradiction creates unsafe operator expectations and can socially engineer users into exposing highly sensitive cloud credentials in chat.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to provide AK/SK and possibly a security token directly in chat for a cloud deployment workflow. Collecting long-lived or privileged secrets through conversational channels risks credential leakage via logs, transcripts, integrations, or accidental reuse, which could lead to full cloud account compromise.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The text says the skill will 'NEVER ask' for AK/SK directly, yet also states it can parse credentials actively provided through conversation input or configuration. This implicitly encourages secret submission through insecure conversational channels and weakens safe-boundary expectations around autonomous secret handling.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

  • Region: Optional, default cn-north-4 (Beijing 4)
text

**Note:** We prioritize getting credentials from environment variables and NEVER ask users to input AK/SK directly. However, if users actively provide credentials through other means (e.g., conversation input, configuration file), we still support parsing.

**Include the regions table and AK/SK instructions (see below).**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
## Parameter Confirmation

> ⛔ **MANDATORY**: User confirmation is required before deployment. No resources can be created without confirmation.

### Confirmation Flow

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The acceptance criteria define successful deployment as being able to log in with a default admin credential, while the same document claims there are no hardcoded credentials. This normalizes insecure defaults and can lead to internet-exposed deployments with known credentials, especially because the skill also expects port 8000 to be reachable publicly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command examples show AK/SK values passed directly on the command line, which commonly exposes secrets via shell history, process listings, logs, and terminal recording tools. Even if the sample values are placeholders, the documentation teaches an unsafe operational pattern for handling cloud credentials.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 16)May include surrounding context.

md
# If not installed, use package manager
# Ubuntu/Debian
sudo apt update && sudo apt install python3 python3-pip -y

# CentOS/RHEL
sudo yum install python3 python3-pip -y

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

md
# If not installed, use package manager
# Ubuntu/Debian
sudo apt update && sudo apt install python3 python3-pip -y

# CentOS/RHEL
sudo yum install python3 python3-pip -y

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to download and immediately execute a remote shell script via curl and bash without any integrity verification, signature check, or warning about the risks. If the hosting location is compromised, DNS/TLS is intercepted, or the script changes unexpectedly, users could execute arbitrary code on their systems.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 120)May include surrounding context.

✅ 解决方案:

bash
# Check file permissions
ls -la ~/.config/hcloud/

# Fix permissions
chmod 600 ~/.config/hcloud/config.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 123)May include surrounding context.

ls -la ~/.config/hcloud/

Fix permissions

chmod 600 ~/.config/hcloud/config.json

text

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document shows AK/SK-style credentials inline in a verification command, which can normalize copying secrets directly into shell history, docs, screenshots, or logs. In a cloud deployment skill that relies on Huawei Cloud AK/SK authentication, this increases the chance that users will handle real long-lived credentials insecurely and accidentally disclose them.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/deploy_sqlbot.py:524

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/huawei_cloud_ecs.py:280