Back to skill

Security audit

huawei-cloud-flexus-l-server-hermes-deployment

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Huawei Cloud Hermes deployment skill, but it needs Review because it can create paid auto-renewing cloud resources and make bot/gateway access broadly open without clear disclosure.

Install only if you are comfortable granting Huawei Cloud credentials that can create paid resources and run remote scripts. Use temporary least-privilege credentials, avoid passing secrets on the command line, review billing settings before deployment, and manually restrict Feishu/WeCom and gateway user access after channel setup or before exposing the bot.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/lib.py:464
Finding

Channel configuration silently enables unrestricted bot and gateway access

Content
View full analysis

Vulnerability Details

File Location: scripts/lib.py:464-474
Vulnerability Type: Access-control weakening through permissive defaults
Risk Level: High

Vulnerable code:

bash
if [ "$BOT_PLATFORM" = "feishu" ]; then
    echo "Configuring Feishu channel..."
    set_env_variable "$ENV_PATH" "FEISHU_APP_ID" "$FEISHU_APP_ID"
    set_env_variable "$ENV_PATH" "FEISHU_APP_SECRET" "$FEISHU_APP_SECRET"
    set_env_variable "$ENV_PATH" "FEISHU_DOMAIN" "feishu"
    set_env_variable "$ENV_PATH" "FEISHU_CONNECTION_MODE" "websocket"
    set_env_variable "$ENV_PATH" "FEISHU_ALLOW_ALL_USERS" "true"
    set_env_variable "$ENV_PATH" "FEISHU_ALLOWED_USERS" ""
    set_env_variable "$ENV_PATH" "FEISHU_GROUP_POLICY" "open"
    set_env_variable "$ENV_PATH" "GATEWAY_ALLOW_ALL_USERS" "true"
    echo "✅ Feishu configuration written successfully"

elif [ "$BOT_PLATFORM" = "wecom" ]; then
    echo "Configuring WeCom channel..."
    set_env_variable "$ENV_PATH" "WECOM_BOT_ID" "$WECOM_BOT_ID"
    set_env_variable "$ENV_PATH" "WECOM_SECRET" "$WECOM_SECRET"
    set_env_variable "$ENV_PATH" "GATEWAY_ALLOW_ALL_USERS" "true"
    echo "✅ WeCom configuration written successfully"
fi

Technical Analysis

The channel-installation template does more than install the credentials selected by the administrator. For Feishu, it explicitly enables all users, clears the user allowlist, opens the group policy, and enables unrestricted gateway access. For WeCom, it also enables unrestricted gateway access.

The remote configuration script is selected and populated by install_channel_remote in scripts/lib.py:664-705. The normal channel workflow invokes that function from scripts/channels.py:141-145, causing Huawei Cloud COC to execute the generated script on the selected Hermes instance. The script normally executes with root privileges because the documented and implemented default execution user is root.

Interactive ...[truncated 2184 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default FEISHU_ALLOW_ALL_USERS and GATEWAY_ALLOW_ALL_USERS to false.
  2. Require explicit administrator-provided user and group allowlists before enabling the channel.
  3. Do not clear FEISHU_ALLOWED_USERS or overwrite existing access-control settings unless the administrator explicitly requests replacement.
  4. Expose public access as a clearly named opt-in option, such as --allow-all-users, rather than enabling it as an undocumented side effect.
  5. Display the resulting authorization policy before execution and require explicit confirmation when public access is requested. Require the same explicit authorization in non-interactive mode through a dedicated flag.
  6. Validate that an allowlist is non-empty whenever unrestricted access is disabled.
  7. Apply least-privilege execution where possible and restrict the COC script to modifying only the necessary channel settings.
  8. Add automated tests asserting that channel setup preserves restrictive access-control defaults unless an explicit public-access option is supplied.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill performs additional credential-driven cloud operations such as UniAgent status checks and interactive AK/SK/token collection that are not clearly reflected in the declared purpose. In a high-privilege cloud deployment context, incomplete disclosure reduces informed consent and can normalize supplying sensitive credentials to a broader set of actions than users expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill performs additional credential-driven cloud operations such as UniAgent status checks and interactive AK/SK/token collection that are not clearly reflected in the declared purpose. In a high-privilege cloud deployment context, incomplete disclosure reduces informed consent and can normalize supplying sensitive credentials to a broader set of actions than users expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill performs additional credential-driven cloud operations such as UniAgent status checks and interactive AK/SK/token collection that are not clearly reflected in the declared purpose. In a high-privilege cloud deployment context, incomplete disclosure reduces informed consent and can normalize supplying sensitive credentials to a broader set of actions than users expect.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib.py (reported line 46)May include surrounding context.

python
# Default configuration
DEFAULT_BASE_URL = "https://api.modelarts-maas.com/v2"
DEFAULT_CONFIG_PATH = "/home/hermes/.hermes/config.yaml"
DEFAULT_ENV_PATH = "/home/hermes/.hermes/.env"

class Credentials:
    """Credentials for Huawei Cloud temporary access"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib.py (reported line 1418)May include surrounding context.

python
# Default configuration
DEFAULT_BASE_URL = "https://api.modelarts-maas.com/v2"
DEFAULT_CONFIG_PATH = "/home/hermes/.hermes/config.yaml"
DEFAULT_ENV_PATH = "/home/hermes/.hermes/.env"

class Credentials:
    """Credentials for Huawei Cloud temporary access"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/smoke_test.py (reported line 49)May include surrounding context.

python
# Default configuration
DEFAULT_BASE_URL = "https://api.modelarts-maas.com/v2"
DEFAULT_CONFIG_PATH = "/home/hermes/.hermes/config.yaml"
DEFAULT_ENV_PATH = "/home/hermes/.hermes/.env"

class Credentials:
    """Credentials for Huawei Cloud temporary access"""

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instance creation flow performs billable cloud provisioning with is_auto_pay=true and is_auto_renew=true, causing real financial and infrastructure changes. Because there is no explicit warning or confirmation gate in the function, accidental or coerced use could silently create recurring charges and persistent resources.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/lib.py (reported line 336)May include surrounding context.

python
echo "Installing yq..."
    # Try package manager installation
    if command -v apt-get &> /dev/null; then
        sudo apt-get update -qq && sudo apt-get install -y -qq yq 2>/dev/null
    elif command -v yum &> /dev/null; then
        sudo yum install -y -q yq 2>/dev/null
    fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib.py (reported line 436)May include surrounding context.

python
FEISHU_APP_SECRET='${feishu_app_secret}'
WECOM_BOT_ID='${wecom_bot_id}'
WECOM_SECRET='${wecom_secret}'
ENV_PATH='/home/hermes/.hermes/.env'

echo "⚙️  Configuring bot channel..."
echo " - Target Platform: $BOT_PLATFORM"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib.py (reported line 1439)May include surrounding context.

python
echo "  --wecom_bot_id      WeCom Bot ID"
    echo "  --wecom_secret      WeCom Secret"
    echo "  --config_path       config.yaml path (default: $DEFAULT_CONFIG_PATH)"
    echo "  --env_path          .env file path (default: $DEFAULT_ENV_PATH)"
    echo ""
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib.py (reported line 1637)May include surrounding context.

python
echo "  --wecom_bot_id      WeCom Bot ID"
    echo "  --wecom_secret      WeCom Secret"
    echo "  --config_path       config.yaml path (default: $DEFAULT_CONFIG_PATH)"
    echo "  --env_path          .env file path (default: $DEFAULT_ENV_PATH)"
    echo ""
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares broad operational capabilities in practice—credentials handling, networked cloud control, shell execution, and file access—but does not declare any explicit tool scope or permission boundaries. For a deployment skill that can create resources and execute remote operations, missing scope declarations increases the chance of unintended or overbroad execution by an agent or caller.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are broad and action-oriented, such as 'Deploy Hermes' and 'Configure Model', without boundaries indicating required confirmation, target account, or whether destructive cloud actions will occur. In a skill capable of provisioning resources and performing remote execution, loose activation criteria raise the risk of accidental invocation and unintended cloud changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document's own security rules say AK/SK/tokens must not appear in commands or conversation, yet the core command examples repeatedly pass secrets as CLI arguments. Command-line secrets are commonly exposed through shell history, process listings, logs, CI output, and telemetry, making credential compromise plausible and severe in a cloud-administration skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation provides many credential-bearing command examples and does not place a strong, proximate warning on each example that secrets should never be passed on the command line. This is especially dangerous because users often copy-paste examples directly, leading to exposure of cloud AK/SK, session tokens, API keys, and bot secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document recommends a combined IAM policy that grants broad create, execute, query, and delete permissions for compute instances and COC scripts on all resources, but does not clearly warn users that these permissions enable destructive actions and remote script execution. In the context of a one-click deployment skill, operators may apply the policy as-is, expanding blast radius if the skill, account, or credentials are abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly instructs users to pass Huawei Cloud AK/SK on the command line, where secrets may be exposed through shell history, process listings, CI logs, or terminal recordings. In a deployment skill for cloud infrastructure, this is especially risky because the credentials can grant broad control over cloud resources if leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This example passes AK, SK, and an API key directly as command-line arguments, multiplying the chance of credential disclosure via shell history, process inspection, support screenshots, or automation logs. Because this step configures model access, exposure could allow unauthorized cloud actions and misuse of paid model services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The channel configuration example places multiple sensitive values, including cloud credentials and bot application secrets, on the command line without any warning. This creates avoidable exposure of both infrastructure credentials and downstream integration secrets, which could enable unauthorized access to messaging integrations and cloud resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The note in the automated test section normalizes passing credentials via command-line parameters and does so without any cautionary guidance. In testing and CI contexts, command lines are often captured in logs, making this especially likely to leak long-lived access credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes this skill as a one-click deployment and configuration workflow for Hermes, specifically deployment, ModelArts configuration, and robot channel configuration. This file also imports and exposes separate gateway restart, script-execution query, and UniAgent status capabilities, which are not mentioned in the manifest and materially broaden the tool’s behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The menu presents 'Restart Hermes Gateway', 'Query COC script execution result', and 'Query UniAgent status' as first-class user actions. These are distinct capabilities beyond the manifest’s stated deployment, model configuration, and channel configuration workflow, creating a mismatch between claimed purpose and exposed behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/caller.py (reported line 106)May include surrounding context.

python
deploy_parser.add_argument('--security-token', help='Huawei Cloud Security Token (optional, only required for temporary AK/SK, will prompt for input if not provided)')
    deploy_parser.add_argument('--name', help='Instance name (optional, auto-generated by default)')
    deploy_parser.add_argument('--region', choices=REGION_IDS, help='Region ID (optional, default cn-north-4)')
    deploy_parser.add_argument('--non-interactive', action='store_true', help='Non-interactive mode, execute without confirmation')

    maas_parser = subparsers.add_parser('maas', help='Configure ModelArts large model on deployed Hermes instance')
    maas_parser.add_argument('--ak', help='Huawei Cloud AK (supports both long-term and temporary AK, optional, will prompt for input if not provided)')

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/caller.py (reported line 119)May include surrounding context.

python
deploy_parser.add_argument('--security-token', help='Huawei Cloud Security Token (optional, only required for temporary AK/SK, will prompt for input if not provided)')
    deploy_parser.add_argument('--name', help='Instance name (optional, auto-generated by default)')
    deploy_parser.add_argument('--region', choices=REGION_IDS, help='Region ID (optional, default cn-north-4)')
    deploy_parser.add_argument('--non-interactive', action='store_true', help='Non-interactive mode, execute without confirmation')

    maas_parser = subparsers.add_parser('maas', help='Configure ModelArts large model on deployed Hermes instance')
    maas_parser.add_argument('--ak', help='Huawei Cloud AK (supports both long-term and temporary AK, optional, will prompt for input if not provided)')

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/caller.py (reported line 134)May include surrounding context.

python
deploy_parser.add_argument('--security-token', help='Huawei Cloud Security Token (optional, only required for temporary AK/SK, will prompt for input if not provided)')
    deploy_parser.add_argument('--name', help='Instance name (optional, auto-generated by default)')
    deploy_parser.add_argument('--region', choices=REGION_IDS, help='Region ID (optional, default cn-north-4)')
    deploy_parser.add_argument('--non-interactive', action='store_true', help='Non-interactive mode, execute without confirmation')

    maas_parser = subparsers.add_parser('maas', help='Configure ModelArts large model on deployed Hermes instance')
    maas_parser.add_argument('--ak', help='Huawei Cloud AK (supports both long-term and temporary AK, optional, will prompt for input if not provided)')

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib.py:404