Back to skill

Security audit

huawei-cloud-functiongraph-trigger-create

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to create Huawei Cloud scheduled triggers as advertised, but it uses cloud credentials, can create active persistent schedules, and includes unsafe credential/TLS troubleshooting guidance that users should review carefully.

Install only if you are comfortable granting a tool Huawei Cloud permissions to create scheduled FunctionGraph triggers. Use least-privilege, preferably temporary credentials; do not echo or paste real AK/SK values into shared terminals or logs; keep TLS certificate verification enabled; create triggers DISABLED first for testing; and verify the function URN, region, schedule, and cleanup target before running commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/sdk-installation-guide.md:122
Finding

TLS Certificate Verification Disabled in SDK Troubleshooting Guidance

Content
View full analysis

Vulnerability Details

File Location: references/sdk-installation-guide.md, lines 122–134
Vulnerability Type: Improper certificate validation
Risk Level: Medium

python
# Disable SSL verification (not recommended for production)
from huaweicloudsdkcore.http.http_config import HttpConfig

config = HttpConfig.get_default_http_config()
config.ignore_ssl_verification = True

client = FunctionGraphClient.new_builder() \
    .with_http_config(config) \
    .with_credentials(credentials) \
    .with_region(region) \
    .build()

Technical Analysis

The troubleshooting guide instructs users to set ignore_ssl_verification to True on an authenticated Huawei Cloud SDK client. This disables validation of the remote server's TLS certificate while the client continues to use cloud credentials.

The warning that the configuration is “not recommended for production” does not technically prevent its use. If a user follows this procedure to work around an SSL error, the client can accept a certificate presented by an untrusted network intermediary. This breaks the server-authentication boundary that TLS is intended to enforce.

Attack Path

  1. A user encounters a certificate error and applies the documented troubleshooting configuration.
  2. The user performs authenticated FunctionGraph API operations using the resulting client.
  3. An attacker with a network interception position, such as control over a proxy, gateway, or hostile network, presents an untrusted certificate.
  4. Because certificate verification is disabled, the SDK accepts the attacker's endpoint rather than rejecting the connection.
  5. The attacker can observe authenticated requests, manipulate API responses, and potentially replay captured valid requests where the service permits replay.

Impact Assessment

Exploitation requires a network-positioned attacker and a user who has enabled the documented bypass. The exposed scope i ...[truncated 448 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to disable TLS certificate verification.
  • Direct users to repair the underlying trust configuration, such as installing the correct CA bundle, configuring an enterprise proxy CA, correcting the system clock, or updating the certificate store.
  • Keep certificate verification enabled for every authenticated Huawei Cloud request.
  • If an insecure connectivity diagnostic is unavoidable, isolate it from the authenticated SDK client, require an explicit opt-in, and prevent credentials or privileged API requests from being used during the test.
  • Add documentation explaining that bypassing certificate validation permits endpoint impersonation and must not be used as a general SSL troubleshooting solution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear mismatch between the declared purpose and the actual code. The description claims the skill creates and configures scheduled TIMER triggers for Huawei Cloud FunctionGraph, but the code is only a basic timer-invoked function handler. It merely processes an invocation, logs a JSON result, and returns it. No API calls, configuration logic, trigger creation, scheduling setup, or cron expression handling are present. The code appears to be an example function that could be executed by a timer, not a tool for creating or configuring such triggers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is infrastructure/configuration oriented: creating and configuring scheduled TIMER triggers for Huawei Cloud FunctionGraph. The supplied code is only a runtime function handler that executes upon invocation and logs/returns event data with a timestamp. There is no logic for interacting with Huawei Cloud APIs, defining trigger metadata, setting cron expressions, or configuring FunctionGraph triggers. This is a material mismatch in primary purpose.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/create_trigger.py (reported line 254)May include surrounding context.

python
parser.add_argument('--status', choices=['ACTIVE', 'DISABLED'], default='ACTIVE',
                        help='Trigger status: ACTIVE (default) or DISABLED')
    parser.add_argument('--user-event', default='', help='Additional user event data')
    parser.add_argument('--skip-check', action='store_true',
                        help='Skip function existence check')

    args = parser.parse_args()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs use of sensitive cloud credentials via environment variables (HUAWEI_AK, HUAWEI_SK, project and region identifiers) but does not declare any explicit tool scope, permissions, or allowed-tools boundary. In an agent environment, missing scope declarations can let the skill access or encourage access to secrets more broadly than intended, increasing the risk of credential exposure or unauthorized cloud changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes broad trigger phrases such as 'timer', 'cron', 'periodic task', and generic schedule-related terms in both English and Chinese. In an agent ecosystem, overly broad invocation cues can cause the skill to activate in contexts where the user did not intend to create or modify cloud triggers, potentially leading to unintended operational changes or prompting for sensitive cloud configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs users to export long-lived cloud credentials as shell environment variables without any warning about shell history, process inspection, shared terminal sessions, or safer alternatives. In a skill that guides real cloud operations, this can lead to accidental credential exposure in logs, screenshots, CI output, or multi-user environments, enabling unauthorized access to Huawei Cloud resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cleanup section includes a trigger deletion command with no prominent warning, confirmation step, or guidance to ensure the target is a non-production test trigger. In an infrastructure-management skill, users may copy-paste commands directly, and an incorrect function URN or trigger ID could delete active production scheduling, causing outages or missed jobs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs users to print credential-bearing environment variables directly to the terminal to troubleshoot authentication. This can expose secrets through terminal scrollback, shell history capture workflows, screen sharing, logging/recording tools, or copied support transcripts. In an SDK installation guide for cloud administration, this is more dangerous because the values are high-value AK/SK credentials for a cloud account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation provides working sample code to disable SSL verification and labels it only as 'not recommended for production,' which understates the risk. Disabling certificate validation enables man-in-the-middle attacks, allowing interception or tampering of API traffic, including cloud credentials and administrative requests. In the context of managing FunctionGraph triggers over a cloud SDK, this can directly compromise account operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes executable code that reads HUAWEI_AK, HUAWEI_SK, and project information from environment variables. The surrounding documentation does not warn users that the script consumes sensitive credentials or advise safe handling, which fits the missing-warning criteria for markdown files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool performs a state-changing cloud action that can immediately create an ACTIVE TIMER trigger, causing future automatic executions of the target function. In an agent skill context, this is dangerous because a user may not fully realize that a single invocation establishes persistent scheduled behavior with ongoing cost, operational, or destructive effects beyond the current session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.