Back to skill

Security audit

huawei-cloud-flexus-l-server-ops

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Huawei Cloud operations tool, but it can change cloud servers and some safeguards are only written in instructions, not enforced by the scripts.

Install only if you intentionally want an agent to operate Huawei Cloud Flexus L resources. Use least-privilege temporary credentials, avoid pasting AK/SK/token values into chat or command lines, verify the target instance manually before lifecycle or password operations, and treat stop/reboot/password reset/update actions as requiring explicit human confirmation outside the script itself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lifecycle.py:20
Finding

Destructive ECS lifecycle operations lack enforced confirmation and resource-scope validation

Content
View full analysis

Vulnerability Details

File Location: scripts/lifecycle.py, lines 20–45 and 80–87
Vulnerability Type: Missing authorization safeguards for destructive cloud operations
Risk Level: High

Complete Code Snippet

python
def manage_servers(action: str, server_ids: list, region: str = "cn-north-4", reboot_type: str = "SOFT", auth: AuthManager = None):
    """Manage Flexus L instance lifecycle (start/stop/reboot)"""
    action = action.lower()
    if action not in ["start", "stop", "reboot"]:
        raise ValueError(f"Invalid action: {action}, must be start/stop/reboot")

    auth = auth or AuthManager()
    if not auth.is_configured():
        raise ValueError("Please set environment variables HW_ACCESS_KEY, HW_SECRET_KEY, HW_SECURITY_TOKEN or provide --ak --sk parameters")

    client = auth.get_ecs_client(region)
    server_id_list = [ServerId(id=sid) for sid in server_ids]

    try:
        if action == "start":
            request = BatchStartServersRequest(body=BatchStartServersRequestBody(
                os_start=BatchStartServersOption(servers=server_id_list)))
            response = client.batch_start_servers(request)
        elif action == "stop":
            request = BatchStopServersRequest(body=BatchStopServersRequestBody(
                os_stop=BatchStopServersOption(servers=server_id_list)))
            response = client.batch_stop_servers(request)
        else:  # reboot
            request = BatchRebootServersRequest(body=BatchRebootServersRequestBody(
                reboot=BatchRebootSeversOption(servers=server_id_list, type=reboot_type)))
            response = client.batch_reboot_servers(request)
python
if not server_ids or action not in ["start", "stop", "reboot"]:
    print("ERROR: Invalid parameters. Please provide --instance-id")
    sys.exit(1)

auth = AuthManager(ak=ak, sk=sk, security_token=security_token)
action_name = "Starting" if action == "start" else "Stopping" if action == "stop" else "Rebooting"
pri
...[truncated 2340 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require an explicit confirmation artifact for stop and reboot. Bind it to:

    • The requested action.
    • The complete, normalized instance-ID list.
    • The region.
    • The reboot type where applicable.
    • A short expiration period.
  2. Reject destructive operations when the confirmation artifact is absent, expired, or does not match the exact request.

  3. Before creating the ECS batch request, query Huawei Config and verify every target ID is a child ECS resource of an hcss.l-instance resource. Fail the entire batch if any ID cannot be verified.

  4. Add a dry-run or operation-preview mode that displays the resolved resources and intended action without modifying them.

  5. Separate destructive and non-destructive code paths so direct calls to manage_servers() cannot bypass confirmation and scope validation.

  6. Add automated tests proving that:

    • Stop and reboot fail without confirmation.
    • Confirmation for one target cannot authorize another.
    • Confirmation for stop cannot authorize reboot.
    • Non-Flexus ECS IDs are rejected.
    • Mixed batches containing one unverified ID are rejected.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:83
Finding

TLS certificate verification is disabled for authenticated Huawei Config API requests

Content
View full analysis

Vulnerability Details

File Location: scripts/auth.py, lines 83–90
Vulnerability Type: Improper certificate validation
Risk Level: Medium

Complete Code Snippet

python
def get_config_client(self, region: str = "cn-north-4"):
    """Get Config client (for resource configuration queries)"""
    config = HttpConfig.get_default_config()
    config.ignore_ssl_verification = True
    return ConfigClient.new_builder() \
        .with_http_config(config) \
        .with_credentials(self.get_global_credentials()) \
        .with_region(ConfigRegion.value_of(region)) \
        .build()

Technical Analysis

The Config client explicitly sets ignore_ssl_verification to True. This disables verification of the remote server's TLS certificate for all requests made through this client.

These requests are authenticated using GlobalCredentials, and temporary credentials may include a security token. Disabling certificate verification removes the endpoint-authentication guarantee provided by TLS and permits an active network attacker capable of intercepting traffic to impersonate the Config service.

Config responses are used by query_instances.py to list Flexus L resources, map ECS IDs to Flexus names, obtain traffic-resource identifiers, and present resource identity information. A forged response can therefore corrupt resource discovery and validation results.

Attack Path

  1. A Config-backed command is invoked, such as listing resources, resolving a Flexus name, listing free resources, or querying traffic resources by region.
  2. get_config_client() creates an authenticated client with TLS certificate verification disabled.
  3. An attacker with an active network interception position redirects or intercepts the Config API connection.
  4. The attacker presents an untrusted certificate, which the client accepts.
  5. The attacker impersonates the API endpoint and can observe authenticated request traffic or return forged Config resource ...[truncated 754 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the line that disables certificate verification:
python
config.ignore_ssl_verification = True
  1. Use the Huawei Cloud SDK's default TLS verification behavior and current operating-system CA trust store.

  2. If the environment requires a private certificate authority, configure an explicit, narrowly scoped CA bundle rather than globally disabling verification.

  3. Do not expose a general-purpose command-line option that disables TLS verification for authenticated operations.

  4. Add integration tests confirming that:

    • Valid Huawei Cloud certificates are accepted.
    • Self-signed or hostname-mismatched certificates are rejected.
    • Temporary credential flows retain certificate verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second description-behavior mismatch reinforces that the skill markets itself as a full operations tool while evidence suggests it may only support querying/reporting. Overstating capabilities around password reset and instance control can mislead users into granting elevated trust or credentials to a skill that is not transparently bounded.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second description-behavior mismatch reinforces that the skill markets itself as a full operations tool while evidence suggests it may only support querying/reporting. Overstating capabilities around password reset and instance control can mislead users into granting elevated trust or credentials to a skill that is not transparently bounded.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes access to environment variables holding Huawei Cloud credentials but declares no explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can allow broader-than-expected access to secrets or execution context, increasing the chance of credential misuse or accidental exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level description embeds broad, ambiguous triggers without clearly separating informational queries from sensitive control actions. This increases the chance that normal cloud-ops language will activate the skill unexpectedly, especially where other tools share similar verbs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are broad and overlap with common operational language such as start, stop, reboot, and query instance. In a multi-skill agent environment, this can cause accidental invocation of a sensitive infrastructure skill from ambiguous user requests, leading to unintended cloud operations or exposure of infrastructure metadata.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document first says AK/SK should never be requested directly, then later allows credentials to be supplied via conversation input. That contradiction can normalize secret submission through chat, creating a direct path for credential disclosure in logs, transcripts, model context, or downstream tooling.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

⚠️ Security Note: Temporary credentials are more secure, please prefer using them!

text

**Note:** We prioritize obtaining credentials from environment variables and NEVER ask users to input AK/SK directly. However, we still support parsing credentials if user voluntarily provides them via other methods (e.g., conversation input, config file).

### Step 2: Select Operation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

By permitting credentials to be provided through conversation or config without a strong prohibition and warning, the skill creates a social and procedural path to secret exfiltration. In LLM systems, conversational secrets are especially risky because they may be retained in transcripts, debugging logs, or exposed to other tools in the chain.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The IAM policy documentation grants permissions for listing, querying, power operations, and password reset, but it does not include the permission needed to modify instance information even though the skill advertises that capability. This mismatch can cause operators to over-broaden privileges ad hoc, or lead to runtime authorization failures that undermine safe, predictable operation of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The verification guide instructs users to display credential-related environment variables with env | grep CLOUD_SDK and shows example secret-bearing variables (CLOUD_SDK_AK and CLOUD_SDK_SK) without any caution about secret exposure. This can lead to accidental disclosure in terminals, logs, screenshots, shell history, or shared support output, especially because this skill manages cloud infrastructure operations where leaked credentials could enable unauthorized instance control.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The authentication helper exposes a Config service client even though the skill is described as Flexus L instance operations and traffic/package management. This expands the skill's capability surface beyond its stated scope and violates least privilege, enabling callers to query broader resource configuration data if they can invoke this helper. The danger is increased because the helper centralizes credential use, making unrelated service access easy to consume elsewhere in the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts Access Key, Secret Key, and security token values directly via command-line arguments, which can expose them through shell history, process listings, audit logs, and orchestration telemetry. In an ops-focused cloud administration skill, these credentials are highly sensitive because they can grant broad control over infrastructure and billing-related resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instructions direct the agent to provide a specific console lookup flow and link to a Chinese-localized help document, but do not offer the user a language or locale choice. This can violate language/locale policy expectations when the user has not opted into Chinese-language support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function converts timestamps to Beijing time unconditionally and the displayed 'Created' value always uses that locale-specific timezone. This is a natural-language policy concern because the file imposes a specific locale/timezone behavior without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:309