Back to skill

Security audit

huawei-cloud-evs-disk-create

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for creating Huawei Cloud EVS disks, but it asks users to install and authorize high-impact cloud tooling in ways that are broader and less verified than necessary.

Review this skill carefully before installing. Use a verified Huawei Cloud CLI installation source where possible, avoid silent or root installer modes unless necessary, prefer the documented minimum custom IAM policy over EVS FullAccess, and require explicit confirmation before any single or batch disk creation because it can incur cloud costs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This is a classic external script fetching pattern: 'curl' retrieves a remote installer and 'bash' executes it locally. That creates a direct code execution path from a mutable remote resource to the user's machine, making compromise of the download source or script content immediately dangerous.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 14)May include surrounding context.

Linux and MacOS System Installation

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

The above command downloads KooCLI to "/usr/local/hcloud/" directory by default and moves it to "/usr/local/bin/" directory for convenient use of hcloud command in any directory (before completing this step, please ensure PATH system variable contains "/usr/local/bin/" path).

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The silent install variant preserves the same remote-code-execution risk as the standard command while also suppressing interactive checkpoints. Because it may be run unattended and can modify system directories, a compromised script could make broad changes with less user scrutiny.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 22)May include surrounding context.

If you want to use default configuration and skip interactive mode, you can add "-y" at the end of the command, as follows:

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Windows System Installation

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes very generic phrases such as 'cloud disk', 'EVS disk', and 'create disk', which can cause the skill to activate in conversations that are only loosely related to Huawei Cloud EVS. Over-broad activation increases the chance that the agent invokes cloud-management guidance in the wrong context, leading to unintended operational actions or confusing users into supplying infrastructure parameters unnecessarily.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 135)May include surrounding context.

❌ Incorrect

text
Assistant: Creating disk test-disk now...  # Incorrect: no confirmation prior to write operation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to download and immediately execute a shell script from the network with no integrity verification, code review step, or safety warning. If the hosting location, transport path, or script content is compromised, users could run arbitrary commands on their systems, potentially with elevated privileges given the note about switching to root.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Documenting a silent '-y' installation mode without warning removes the user's opportunity to review prompts before the installer performs filesystem and PATH modifications. In combination with a remotely fetched installer, this increases the chance of unnoticed unsafe or unwanted changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file hardcodes accepted trigger phrases in specific languages and does not state that users may interact in their preferred language or locale. This can be a language-policy issue if organizational guidance requires user choice rather than fixed-language assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document contradicts its own least-privilege guidance by explicitly recommending the broad EVS FullAccess system policy for a skill that only needs a small set of EVS actions. This can lead operators to grant unnecessary write and administrative capabilities across EVS resources, increasing blast radius if the skill is misused, compromised, or invoked with unintended parameters.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.