Back to skill

Security audit

huawei-cloud-flexus-l-server-manage

Security checks for vulnerabilities and agentic risk

Overview

This skill is intended for Huawei Cloud server lifecycle management, but it handles billing/destructive cloud operations while disabling TLS verification and recommending broad privileges.

Review this carefully before installing. Use only a dedicated least-privilege Huawei Cloud user or temporary credentials, prefer dry-run first, avoid the --confirm shortcut unless you have checked the exact resource IDs and billing impact, and do not use this version for privileged operations unless TLS verification is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/flexus_lifecycle.py:331
Finding

TLS Certificate Verification Disabled for Privileged Cloud Operations

Content
View full analysis

Vulnerability Details

File Location: scripts/flexus_lifecycle.py, lines 331–334 and 460–468
Vulnerability Type: Improper certificate validation (CWE-295)
Risk Level: High

Vulnerable code — lines 331–334:

python
config = HttpConfig.get_default_config()
config.ignore_ssl_verification = True

client = BssClient.new_builder() \

Vulnerable code — lines 460–468:

python
resp = requests.request(
    signed_request.method,
    full_url,
    headers=signed_request.header_params,
    data=signed_request.body,
    verify=False,
    timeout=60
)

Technical Analysis

The lifecycle client explicitly disables TLS certificate verification in two privileged request paths:

  • The BSS SDK client used by renewal and unsubscribe operations is configured with ignore_ssl_verification = True.
  • The direct HCSS request used to create an instance passes verify=False to requests.request.

Consequently, HTTPS encryption may still be negotiated, but the client does not authenticate the remote endpoint. An attacker able to intercept or redirect network traffic can present an arbitrary certificate without causing the requests to fail.

These requests contain signed authorization headers and, when temporary credentials are used, an X-Security-Token header. They also carry resource identifiers and account-changing requests involving purchases, renewals, or subscription cancellation.

The issue is reachable during any non-dry-run create, renewal, or unsubscribe operation. The CLI confirmation mechanism limits accidental execution but does not protect the connection after the user authorizes the operation.

Attack Path

  1. The user authorizes a create, renewal, or unsubscribe operation and supplies Huawei Cloud credentials.
  2. An attacker with a network interception or traffic-redirection position redirects the relevant Huawei Cloud connection to an attacker-controlled TLS endpoint. ...[truncated 1171 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove config.ignore_ssl_verification = True and retain the Huawei Cloud SDK's default certificate validation.
  • Remove verify=False from requests.request, allowing Requests to use its trusted CA store.
  • If an enterprise or private CA is required, accept an explicitly configured CA bundle and pass its path through the SDK configuration and verify parameter. Do not silently fall back to disabled verification.
  • Fail closed when certificate validation fails and return a sanitized error without retrying through an insecure transport.
  • Add tests that verify invalid, expired, hostname-mismatched, and self-signed certificates are rejected across creation, renewal, and unsubscribe paths.
  • Prefer current system and application CA bundles and document secure proxy configuration for environments that perform authorized TLS inspection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as performing server lifecycle management, but the documented behavior prominently includes fetching and parsing remote documentation data and may not actually implement the destructive or billable lifecycle actions it claims. This mismatch is dangerous because users and orchestrators may authorize sensitive credentials and execution privileges under false assumptions, enabling unintended network activity and unsafe automation decisions.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
---

## ⚠️ Conversation Display Guidelines (Important)

**When displaying "Available Specifications" or "Available Images" to users in conversation, you MUST immediately append the following note:**

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that rely on shell execution, environment variables, and network access, but it does not declare an explicit tool scope such as allowed-tools or permissions. That omission weakens containment and review because an agent may grant broader runtime capabilities than users expect, especially for a skill that handles cloud credentials and billing operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match routine cloud-administration language, which increases the chance that this skill is invoked in contexts the user did not intend. Because the skill may access credentials, perform network operations, and initiate billable or destructive workflows, accidental activation materially increases operational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger rules include ambiguous phrases like generic purchase, renewal, and unsubscribe language without hard constraints tying them to Huawei Cloud Flexus L. In an agentic environment, this can cause misrouting into a skill that handles cloud credentials and subscription actions, leading to unintended requests or billing-related operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This API reference documents billable and destructive operations including instance creation, renewal, and unsubscription, but it provides no warning about financial impact, resource deletion risk, or the need for explicit user confirmation before execution. In an agent skill context, that omission is dangerous because downstream implementations may treat these operations as routine and perform costly or irreversible actions without adequate consent safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation grants and recommends permissions that can directly create paid orders, renew services, unsubscribe instances, and apply refunds, but it does not clearly warn operators about the billing and service-impacting consequences of those actions. In the context of a server lifecycle management skill, this increases the risk of accidental financial charges, unintended service termination, or misuse of over-broad access, especially when paired with the recommendation to assign a broad built-in policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The listed Windows images all use _ch variants, which indicates a Chinese-language or locale-specific image selection. The document does not offer alternative locale options or explain that this locale restriction is intentional, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to grant broad permissions such as HCSS FullAccess and BSS Administrator, which can enable destructive or financially impactful actions, but it does not warn about the risks of overprivilege or advise limiting scope. In a skill that manages server creation, renewal, and unsubscription, this omission increases the chance that users grant unnecessarily powerful access that could later be abused by the skill, an operator, or compromised credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes managing Flexus L lifecycle operations such as create, renew, and unsubscribe. Here the skill invokes another script with subprocess to fetch dynamic spec data, adding a code-execution capability that is not declared in the skill purpose and is not inherently required for lifecycle management itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/flexus_lifecycle.py (reported line 75)May include surrounding context.

python
if data_type != "all":
            cmd.append(f"--{data_type}")
        
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

The code disables TLS certificate verification for the instance creation API request, and elsewhere globally suppresses related warnings. This makes the cloud control-plane request susceptible to man-in-the-middle interception or response tampering, which is especially dangerous because the request is authenticated and carries cloud account operations that can create billable resources.

Content

Scanner excerpt · scripts/flexus_lifecycle.py (reported line 466)May include surrounding context.

python
full_url,
            headers=signed_request.header_params,
            data=signed_request.body,
            verify=False,
            timeout=60
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The unsubscribe function performs an irreversible destructive cloud action directly when called as a library function, with no built-in confirmation, warning, or policy gate. Although the CLI wrapper asks for confirmation, any other caller of this function can trigger immediate unsubscription programmatically, increasing the risk of accidental or unauthorized destructive operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says this skill manages Flexus L server lifecycle operations such as create, renew, and unsubscribe. This file instead fetches and parses public documentation pages in real time to extract spec and image metadata, which is a distinct documentation-scraping capability rather than lifecycle management itself.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The implemented behavior is not limited to creating, renewing, or unsubscribing Flexus L instances; it downloads an external support page and extracts instance specs, regions, and system image compatibility data. That is a meaningful functional scope extension beyond the manifest's described lifecycle-management operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads access key, secret key, and security token values from environment variables, which is a sensitive credential access pattern. While operationally expected, there is no nearby warning or explanatory comment advising users that the tool consumes cloud credentials from the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The request headers hard-code Accept-Language: zh-CN,zh;q=0.9, which imposes a Chinese locale preference for all requests. This is a natural-language/locale policy concern because the skill does not offer any user choice or document why a fixed locale is required.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pyasn1 has 10 known advisory(ies) (CVE-2026-23490 (pyasn1 has a DoS vulnerability in decoder); CVE-2026-59885 (pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing al); CVE-2026-59886 (pyasn1: Uncontrolled resource consumption when converting decoded REAL values) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: simplejson has 2 known advisory(ies) (CVE-2014-4616 (simplejson before 2.6.1 vulnerable to array index error); CVE-2014-4616 (simplejson before 2.6.1 vulnerable to array index error)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: setuptools has 10 known advisory(ies) (CVE-2013-1633 (Setuptools vulnerable to Man-in-the-middle attacks); CVE-2025-47273 (setuptools has a path traversal vulnerability in PackageIndex.download that lead); CVE-2024-6345 (setuptools vulnerable to Command Injection via package URL) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/flexus_lifecycle.py:466