Back to skill

Security audit

huawei-cloud-find-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with Huawei Cloud skill discovery, but it installs persistent telemetry tooling and other skills through broad remote install commands that deserve review before use.

Install only if you are comfortable with default-on anonymous telemetry, a persistent skill-quality-cli under your user environment, and remote installation of additional Huawei Cloud skills through npx. Set SKILL_QUALITY_REPORT=0 before use if telemetry is not acceptable, and review the matched skill before allowing installation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill's declared purpose omits mandatory telemetry transmission of search exposure and installation events, which is behaviorally significant and security-relevant. Undisclosed or understated outbound reporting can cause unexpected data egress and undermine informed consent, even if the transmitted fields are described as limited.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill's declared purpose omits mandatory telemetry transmission of search exposure and installation events, which is behaviorally significant and security-relevant. Undisclosed or understated outbound reporting can cause unexpected data egress and undermine informed consent, even if the transmitted fields are described as limited.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill's declared purpose omits mandatory telemetry transmission of search exposure and installation events, which is behaviorally significant and security-relevant. Undisclosed or understated outbound reporting can cause unexpected data egress and undermine informed consent, even if the transmitted fields are described as limited.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's declared purpose omits mandatory telemetry transmission of search exposure and installation events, which is behaviorally significant and security-relevant. Undisclosed or understated outbound reporting can cause unexpected data egress and undermine informed consent, even if the transmitted fields are described as limited.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The statement that the skill is 'read-only' materially contradicts the documented behavior: it installs software, modifies filesystem locations, may alter PATH reachability, and installs other skills. This kind of misrepresentation is dangerous because it can cause users or review systems to underestimate host-modification risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands, accesses environment variables, and performs outbound network requests, but it does not declare any explicit tool scope or permissions boundary. This makes the skill's effective capabilities broader than what a reviewer or runtime policy might expect, increasing the risk of unintended command execution, data egress, and environment modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to invoke the skill to "search, list, query, discover, browse, find and install any Huawei Cloud agent skill," which bundles many common intent words and broadens activation beyond a narrowly defined trigger. Although examples are provided, the activation boundary is still unclear because it does not specify exclusion cases or a strict trigger scope, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill claims to handle only discovery and installation, but it also performs mandatory outbound telemetry and reporting unrelated to the user's core task. Even with limited payloads, default-on reporting broadens the attack surface and creates privacy and policy concerns because network egress becomes part of every invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill requires installation and auto-linking of an external telemetry CLI into the user's environment, including PATH-related changes and local binary placement. That goes beyond simple discovery and creates a persistent trust anchor on the host, increasing supply-chain and local-environment risk if the fetched tool is compromised or later abused.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx skills without pinning an exact package version introduces supply-chain risk because a future or compromised package release could change behavior and execute untrusted code at install time. In this skill, those commands are part of the documented install path, so the unpinned dependency directly affects users who follow the instructions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

macOS

brew install python3

Ubuntu/Debian

sudo apt-get install python3

Windows — download installer from python.org, check "Add Python to PATH"

text
2. **Verify after install**: Run `python --version` again to confirm Python 3.6+ is available

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill performs an outbound POST request to a remote telemetry endpoint during installation, sending a constructed skill_id and doing so as a mandatory step in the workflow. External transmission is security-relevant because it creates data egress, expands network trust, and can be unexpected in environments that allow discovery but prohibit unsolicited reporting.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

⚠️ MANDATORY (质量上报): 安装计数请求同样用 run 包装, 保证安装流程触发质量上报。

bash
skill-quality-cli run --skill-name huawei-cloud-find-skills -- curl -s -X POST "https://devdata2.huaweicloud.com/rest/developer/fwdo/rest/developer/servlet/hdskillservice/v1/obs/findcounts/increment" -H "Accept: application/json, text/plain, */*" -H "Content-Type: application/json" -H "Origin: https://skills.huaweicloud.com" -H "Referer: https://skills.huaweicloud.com/" -d "{\"skill_id\":\"skills/<category>/<service>/<skill-name>\"}"

This is a fire-and-forget request. Do NOT block the install flow on its success or failure.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The installation workflow relies on npx skills add without a pinned version, allowing code from the current registry state to be executed on the user's machine. Because this step installs additional skills from remote repositories, an attacker could chain package compromise with malicious skill content for significant code-execution impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The acceptance criteria explicitly require fire-and-forget reporting of each returned skill name to an install-count API, but the document does not disclose this outbound telemetry to users or require consent. Even if only skill names are sent, this leaks user search/discovery behavior to an external service and creates an undisclosed data flow from a nominally read-only search feature.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide mandates executing bash scripts/ensure_cli.sh on every skill run even though this skill is only for discovering Huawei Cloud skills, creating unnecessary code execution and expanding the trust boundary. Because the referenced CLI is for telemetry rather than the core browsing function, users may be induced to run local scripts with side effects unrelated to the stated purpose, which is a supply-chain and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states telemetry is automatic and only provides an opt-out afterward, without clearly warning users before installation or execution that reporting may occur. In a skill whose purpose is simply to find or browse other skills, silent or poorly disclosed telemetry is more dangerous because users would not reasonably expect operational reporting to be enabled as a condition of use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that search results trigger fire-and-forget reporting to an install-count API, but it does not clearly warn users that network telemetry is being sent. Silent reporting creates a privacy and trust issue because users may unknowingly transmit usage data during what appears to be a local search/verification workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.