Back to skill

Security audit

huawei-cloud-flexus-l-server-flexusagent-deployment

Security checks for vulnerabilities and agentic risk

Overview

The skill’s deployment purpose is real and mostly disclosed, but it handles powerful cloud credentials and admin passwords in unsafe ways that warrant manual review before installation.

Install only if you are comfortable granting this skill cloud-provisioning authority and COC remote execution rights. Use least-privilege temporary Huawei credentials, avoid command-line secrets where possible, do not rely on HTTP for admin or MaaS credentials, rotate any password or token that appears in logs or chat, and review or replace the external curl-to-bash scripts before running password reset or workflow import.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib.py:258
Finding

Huawei Cloud authentication headers are exposed in execution output

Content
View full analysis

Vulnerability Details

File Location: scripts/lib.py:258-259, scripts/lib.py:943
Vulnerability Type: Sensitive authentication data disclosure
Risk Level: High

Complete Code Snippet

python
print(f"Authorization: {headers.get('Authorization')}")
print(f"Request headers: {headers}")
print(f"Request body: {body_str}")

A second request path also prints all signed headers:

python
print(f"Request URL: {url_with_params}")
print(f"Request headers: {headers}")

resp = requests.request(
    "GET",
    url_with_params,
    headers=headers,
    verify=True
)

Technical Analysis

The deployment and UniAgent query paths construct signed Huawei Cloud requests using the supplied access key, secret key, and optional temporary security token. The resulting headers dictionary can contain an Authorization header with the access-key identifier and request signature. For temporary credentials, it can also contain the raw X-Security-Token.

The code prints these headers without redaction. This behavior is reachable during normal deployment and instance-status operations and directly conflicts with the credential-handling requirements in SKILL.md, which prohibit displaying AK/SK/token data.

The dangerous data flow is:

  1. Credentials are loaded from command-line arguments or HW_ACCESS_KEY, HW_SECRET_KEY, and HW_SECURITY_TOKEN.
  2. The Huawei signer generates authenticated request headers.
  3. The complete headers are printed to the process output.
  4. Skill execution output may be retained in conversation history, terminal logs, CI logs, or agent execution records.

Attack Path

  1. A user runs the deployment or instance-query command with valid Huawei Cloud credentials.
  2. The request is signed, including an authorization signature and potentially X-Security-Token.
  3. scripts/lib.py prints the signed authentication headers.
  4. An unauthorized party with access to execution logs, conversation records, or captured terminal ou ...[truncated 953 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all output of Authorization, X-Security-Token, cookies, and complete request-header dictionaries.
  2. Log only non-sensitive metadata, such as:
    • HTTP method
    • Sanitized host and path
    • Generated request ID
    • Response status code
  3. Introduce a centralized redaction function that recursively masks sensitive names, including:
    • Authorization
    • X-Security-Token
    • Cookie and Set-Cookie
    • access_key, secret_key, and API-key fields
  4. Ensure exception messages and SDK diagnostic logging are passed through the same redaction layer.
  5. Add tests asserting that known credential values never appear in captured stdout or stderr.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/passwd.py:93
Finding

FlexusAgent administrator password is printed and required to be echoed in conversation

Content
View full analysis

Vulnerability Details

File Location: scripts/passwd.py:93-97; related instruction at SKILL.md:265-266
Vulnerability Type: Plaintext privileged credential disclosure
Risk Level: Medium

Complete Code Snippet

Executable disclosure:

python
print(f"  Resource ID: {resource_id}")
print(f"  Region: {region_id}")
print(f"  Admin Password: {admin_password}")
print(f"  Timeout: {timeout} seconds")

The Skill instructions separately require the new password to be returned in conversation:

markdown
> **Must Execute After First Deployment**: Must set password after first deployment, otherwise cannot login to Web UI.
> **Mandatory Constraint**: After changing password, reply: `"Web UI: http://<public-ip>:80; Login email: super@dify.com, Password: <new-password>"`

Technical Analysis

The password-change workflow handles a newly selected privileged administrator password. Before changing it, the executable module prints that password in plaintext. The Skill instructions additionally require the agent to repeat the password in its conversational response.

This creates two disclosure channels:

  • Process and Skill execution output from scripts/passwd.py.
  • Persistent agent conversation history mandated by SKILL.md.

Although the user supplies or approves the password, its placement into output and conversation records expands access beyond the authentication channel. Those records may be visible to log operators, agent-platform administrators, support personnel, or anyone who later obtains conversation or terminal history.

Attack Path

  1. A user invokes the password-change workflow and supplies a new administrator password.
  2. scripts/passwd.py prints the complete password as part of the configuration summary.
  3. The password is captured by terminal, orchestration, or agent execution logs.
  4. After the operation, the Skill instructions require the agent to repeat the same password in conversation.
  5. A party with access to ...[truncated 658 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext output with a fixed masked value:
    python
    print("  Admin Password: ********")
    
  2. Use hidden input for interactive password entry by passing hide_input=True.
  3. Remove the SKILL.md requirement to reproduce the password in conversation.
  4. Return only confirmation that the password was changed successfully.
  5. If recovery or transfer is necessary, place the password in a dedicated secret manager or one-time secure channel rather than stdout or conversation history.
  6. Add automated tests that run the password workflow with a sentinel password and verify that it never appears in stdout, stderr, exception text, or generated COC execution output.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib.py:1434
Finding

Documented plaintext HTTP workflow transmits administrator and MaaS credentials without transport protection

Content
View full analysis

Vulnerability Details

File Location: scripts/lib.py:1434-1454; supporting workflow at SKILL.md:205,266,278 and public ingress configuration at scripts/lib.py:1264-1269
Vulnerability Type: Cleartext transmission of authentication secrets
Risk Level: High

Complete Code Snippet

The login function accepts the caller-provided base URL and sends the administrator password to it:

python
# 1. Access homepage or login page to initialize Cookies and get initial CSRF Token
session.get(f"{base_url}/signin", timeout=timeout)

# 2. Prepare login
login_url = f"{base_url}/console/api/login"
login_payload = {
    "email": email,
    "password": base64.b64encode(password.encode("utf-8")).decode("utf-8"),
    "remember_me": True,
}

# Extract CSRF Token from initial Cookies (if any)
initial_csrf = (
        session.cookies.get('csrf_token') or
        session.cookies.get('_csrf_token') or
        session.cookies.get('__Secure-Ns-Csrf-Token')
)
login_headers = {"Content-Type": "application/json"}
if initial_csrf:
    login_headers["X-Csrf-Token"] = initial_csrf

resp = session.post(
    login_url, json=login_payload, headers=login_headers, timeout=timeout
)

The documented and returned service URL is plaintext HTTP:

markdown
- **Web UI**: `http://<public-ip>:80`

The deployment path also creates a public ingress rule by default:

python
protocol: str = "tcp",
port: str = "80",
remote_ip: str = "0.0.0.0/0",
description: str = "Web UI port",
ethertype: str = "IPv4",

Technical Analysis

Base64 is an encoding and does not provide confidentiality. When the documented http://<public-ip>:80 URL is supplied to get_admin_session, the administrator password is sent across the network in recoverable form without TLS.

After login, the authenticated session is used by the MaaS integration flow to install a plugin and submit credential_schema={"api_key": maas_api_key} to the FlexusAgent API. If the base URL uses HTTP, the session cook ...[truncated 1595 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require https:// for all credential-bearing FlexusAgent operations.
  2. Reject HTTP base URLs before the first request:
    python
    parsed = urlparse(base_url)
    if parsed.scheme != "https":
        raise ValueError("HTTPS is required for credential-bearing operations")
    
  3. Provision TLS before password login, plugin installation, or MaaS configuration.
  4. Keep certificate verification enabled and do not add insecure bypasses such as verify=False.
  5. Redirect port 80 to HTTPS only after a valid TLS endpoint exists; do not perform authentication on port 80.
  6. Restrict security-group ingress to user-approved source CIDRs instead of 0.0.0.0/0 where operationally possible.
  7. Rotate any administrator password or MaaS API key previously transmitted through the HTTP workflow.
  8. Add integration tests confirming that HTTP endpoints are rejected before credentials or session cookies are sent.

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/lib.py:980
Finding

Mutable remote shell scripts are downloaded and executed as root without integrity verification

Content
View full analysis

Vulnerability Details

File Location: scripts/lib.py:980-994; execution paths at scripts/lib.py:1031-1069 and scripts/lib.py:1157-1197
Vulnerability Type: Unverified remote payload retrieval and privileged execution
Risk Level: High

Complete Code Snippet

The COC script templates download mutable remote content and pipe it directly into Bash:

python
SCRIPT_TEMPLATES = {
    "change_password": {
        "name": "FlexusAgent-Admin-Password",
        "type": "SHELL",
        "description": "Change FlexusAgent admin user password",
        "risk_level": "LOW",
        "content": '''#!/bin/bash
curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/agent/reset_admin_password.sh | bash -s "${adminPassword}"'''
    },
    "import_dify_app_workflow": {
        "name": "import_dify_app_workflow",
        "type": "SHELL",
        "description": "import dify app workflow on dify server instance",
        "risk_level": "MEDIUM",
        "content": '''curl -sSL https://flexus-config-cn-north-4-product.obs.cn-north-4.myhuaweicloud.com/stable/dify/scripts/import_yml_to_dify.sh | bash -s ${base64String} ${dify_admin_password}'''
    },
}

The generated COC script is executed with a root default:

python
def change_flexusagent_admin_password(
        resource_id: str,
        region_id: str,
        admin_password: str = "",
        timeout: int = 600,
        execute_user: str = "root",
        ak: str = None,
        sk: str = None,
        security_token: str = None,
) -> dict[str, Any]:
python
execute_result = coc_execute_script(
    script_uuid=script_uuid,
    execute_user=execute_user,
    timeout=timeout,
    success_rate=100.0,
    target_instances=target_instances,
    rotation_strategy="CONTINUE",
    ak=ak,
    sk=sk,
    security_token=security_token,
)

Technical Analysis

The package does not contain the scripts that perform password reset an ...[truncated 2256 chars]

Remediation
View remediation

Remediation Suggestions

  1. Package the required password-reset and workflow-import scripts inside the reviewed Skill.
  2. If remote retrieval is unavoidable:
    • Use immutable, versioned object paths.
    • Pin a SHA-256 or stronger digest in the Skill.
    • Download to a controlled file.
    • Verify the digest or trusted digital signature before execution.
    • Abort on any mismatch.
  3. Replace curl | bash with explicit download, verification, and execution stages.
  4. Run the helper under the least-privileged account capable of completing the operation.
  5. Avoid passing passwords on the shell command line; use a protected file descriptor, root-owned input file with restrictive permissions, or a secret-management facility.
  6. Assign a risk level consistent with root-level remote code execution rather than marking the password-reset script as LOW.
  7. Remove generated COC scripts after completion if continued storage is not operationally required.
  8. Record the verified artifact version and digest in non-sensitive audit output.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill also performs cloud-status queries, uses AK/SK/security token credentials for API access, and returns instance access details and default login information without clearly declaring those capabilities. In context, this makes credential use and sensitive infrastructure disclosure less transparent, increasing the risk of misuse or unsafe delegation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill also performs cloud-status queries, uses AK/SK/security token credentials for API access, and returns instance access details and default login information without clearly declaring those capabilities. In context, this makes credential use and sensitive infrastructure disclosure less transparent, increasing the risk of misuse or unsafe delegation.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: huawei-cloud-flexus-l-server-flexusagent-deployment
description: >
  Deploy AI Agent development platform (Dify) on Huawei Cloud Flexus L instance, providing deployment operations, password management, MaaS model configuration, and workflow import capabilities.
  Trigger keywords: deploy flexusagent/一键部署Flexus AI Agent开发平台、change password/修改开发平台管理员密码、change dify password/修改dify平台密码、add maas provider/添加MaaS模型供应商、configure maas model/配置MaaS模型、view workflow/查看AI Agent工作流、import workflow/导入AI Agent工作流
tags:
  - Deploy Flexus AI Agent
  - Deploy A

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a direct instruction to disclose freshly set admin credentials into the conversation, which constitutes secret exfiltration by design. Because the skill manages a publicly reachable web UI on a cloud instance, disclosure of the password could immediately enable unauthorized access if the transcript is exposed.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

md
## Parameter Confirmation

‌‌Before executing any command, the command's parameters must be confirmed.

---

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
| [iam-policies.md](references/iam-policies.md) | IAM permission policies |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instance-creation path prints the Authorization header, full signed request headers, and request body to stdout. These values can expose signed credentials, project identifiers, and sensitive provisioning details in logs, enabling replay, lateral movement, or cloud-account abuse by anyone with log access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The COC helpers allow creation and execution of arbitrary shell/Python/BAT scripts on remote cloud instances, effectively providing remote code execution over managed infrastructure. If abused through prompt injection, unsafe caller input, or compromised upstream logic, an attacker could run destructive commands, steal data, alter services, or establish persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This function executes remote scripts on instances with no built-in interactive confirmation, safety interlock, or explicit risk acknowledgment. In an agent context, that makes sensitive infrastructure changes easier to trigger unintentionally or via adversarial instruction flow.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The password-reset template downloads a shell script from an external URL and immediately pipes it to bash as root. This creates a supply-chain and integrity risk: if the remote file or hosting path is compromised, every execution becomes attacker-controlled privileged code execution on customer instances.

Content

Scanner excerpt · scripts/lib.py (reported line 986)May include surrounding context.

python
"description": "Change FlexusAgent admin user password",
        "risk_level": "LOW",
        "content": '''#!/bin/bash
curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/agent/reset_admin_password.sh | bash -s "${adminPassword}"'''
    },
    "import_dify_app_workflow": {
        "name": "import_dify_app_workflow",

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The workflow-import template also fetches an external shell script and pipes it directly into bash, while passing sensitive data to it. This combines remote code execution, supply-chain exposure, and credential-handling risk in a single step, making compromise especially damaging.

Content

Scanner excerpt · scripts/lib.py (reported line 993)May include surrounding context.

python
"type": "SHELL",
        "description": "import dify app workflow on dify server instance",
        "risk_level": "MEDIUM",
        "content": '''curl -sSL https://flexus-config-cn-north-4-product.obs.cn-north-4.myhuaweicloud.com/stable/dify/scripts/import_yml_to_dify.sh | bash -s ${base64String} ${dify_admin_password}'''
    },
}

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The password-change helper creates and runs a remote script as root to reset an admin password without any built-in warning or second-factor confirmation. In an agent-driven workflow, this could lock out legitimate users or hand administrative control to an attacker if invoked improperly.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow-import helper embeds admin credentials into a remotely executed shell command, exposing secrets to script content, process arguments, remote execution systems, and possibly logs. That creates multiple credential-leak paths and couples privileged credentials to an external-script execution mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Echoing the admin password in plaintext creates a direct credential disclosure channel during a privileged password rotation workflow. In this skill context, the password belongs to the FlexusAgent administrative account, so exposure can enable unauthorized access to the deployment platform and any connected workflows or model configuration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares powerful capabilities such as environment-variable access, network access, and shell execution, but does not explicitly scope or constrain those tools in metadata. In a deployment skill that handles cloud credentials and remote operations, missing tool scope increases the chance of overbroad execution and makes user review and policy enforcement harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to pass AK/SK and tokens on the command line, even though earlier guidance says to avoid exposing secrets. Command-line arguments are commonly exposed through shell history, process listings, logs, and audit tooling, so this weakens credential confidentiality.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
83% confidence
Finding

The skill recommends that, after deployment, the agent automatically proceed with querying instance details and changing the password once the user agrees to the broader step. For costly and privileged cloud actions, bundling multiple sub-actions into an automated workflow can reduce informed consent and increase the chance of unintended changes or disclosures.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
**Execution Order Recommendation**:
1. After deployment completes, **immediately ask user whether to change password (step 2)**
2. After user agrees, AI Agent automatically executes: query instance details → change password → return access information
3. After password change, ask user whether to integrate MaaS model (step 3)
4. If quick AI application deployment is needed, guide user to view and import workflows (steps 4, 5)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The documentation states that querying instance details and changing the password are auto-executed sub-steps. In this context, automation over infrastructure access and credential rotation is risky because it may expose endpoints and alter authentication without a distinct approval boundary for each operation.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
### 2️⃣ Change Admin Password and Get Instance Details (Required)

**⚠️ Important Note**: This step includes two auto-executed sub-steps: First query instance details to get floating IP and resource ID, then change admin password.

**Change Password & Query Instance Details**

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill's security rules say credentials and secrets must never be exposed, but the required reply includes printing the newly set admin password back into the conversation. This contradiction creates a direct secret-disclosure path and trains the agent to exfiltrate sensitive authentication material through chat output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The required password-change response explicitly instructs the agent to disclose the new admin password back to the user without warning or protection. Even if intended for convenience, placing a live password in conversation risks retention in chat logs, screenshots, transcripts, and downstream monitoring systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to pass Huawei Cloud AK/SK and security tokens directly on the command line, which can expose secrets through shell history, process listings, terminal logs, and CI/CD output. In a deployment skill that handles cloud provisioning, these credentials could allow unauthorized access to cloud resources if leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section documents use of administrator passwords and MaaS API keys in command invocations and operational steps without warning that these values are sensitive. Because the skill is specifically for deploying and administering an AI platform, exposed admin credentials or API keys could lead to account compromise, model/provider abuse, or unauthorized workflow access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code accesses Huawei Cloud access key, secret key, and optional security token from environment variables. Although the skill prints status messages elsewhere, it does not disclose to the user that it will read sensitive credentials from the local environment, which falls under the missing-warning criteria for sensitive environment variable access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/caller.py (reported line 117)May include surrounding context.

python
maas_parser.add_argument('--flexusagent-email', type=str, help='FlexusAgent admin email')
    maas_parser.add_argument('--flexusagent-password', type=str, help='FlexusAgent admin password')
    maas_parser.add_argument('--maas-api-key', type=str, help='ModelArts MaaS API Key')
    maas_parser.add_argument('--non-interactive', action='store_true', help='Non-interactive mode, execute without confirmation')

    import_workflow_parser = subparsers.add_parser('import-app-workflow', help='Import Dify app workflow to FlexusAgent instance')
    import_workflow_parser.add_argument('--resource-id', help='L Instance Resource ID')

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/lib.py (reported line 563)May include surrounding context.

python
if not data:
                # Query failed, log and continue
                error_msg = query_result.get("error", {}).get("message", "Unknown error") if isinstance(query_result,
                                                                                                   dict) else "Query failed"
                print(f"Failed to query execution status: {error_msg}")
                time.sleep(wait_interval)
                elapsed_time += wait_interval

Static analysis

No suspicious patterns detected.