Back to skill

Security audit

huawei-cloud-ges-graph

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Huawei Cloud GES management helper, but it can use cloud credentials to mutate, export, and delete data with weak built-in safeguards.

Review this before installing on any production account. Use only least-privilege, test-scoped Huawei Cloud credentials; avoid reusable passwords; do not run graph clearing, bulk deletion, import/export, or OBS object operations unless you have a backup and an explicit target. The transport issues should be fixed before trusting this with sensitive graph data or credentials.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ges_graph_skill.py:138
Finding

Cloud credentials, bearer tokens, and graph data use unauthenticated or plaintext network transport

Content
View full analysis

Vulnerability Details

File Location: scripts/ges_graph_skill.py:138-179, 191-250, 329-367, 506-541; scripts/ges_graph_skill.js:545-603
Vulnerability Type: Disabled TLS certificate verification and plaintext authenticated API transport
Risk Level: High

Technical Analysis

The Python authentication paths explicitly disable TLS certificate verification when sending either the user's password or an AK/SK-authenticated request to the configured IAM endpoint:

python
def _fetch_token_by_password(self, username: str, password: str, domain_name: str = None) -> str:
    url = self.config.get('iam_url')
    project_id = self.config.get('project_id')

    if not url:
        raise Exception("ges_env.csv中缺少iam_url配置")

    headers = {'Content-Type': 'application/json'}

    if domain_name:
        data = {
            'auth': {
                'identity': {
                    'methods': ['password'],
                    'password': {
                        'user': {
                            'name': username,
                            'password': password,
                            'domain': {'name': domain_name}
                        }
                    }
                },
                'scope': {'project': {'id': project_id}}
            }
        }
    else:
        data = {
            'auth': {
                'identity': {
                    'methods': ['password'],
                    'password': {
                        'user': {
                            'name': username,
                            'password': password
                        }
                    }
                },
                'scope': {'project': {'id': project_id}}
            }
        }

    resp = requests.post(url, headers=headers, json=data, timeout=30, verify=False)

The AK/SK authentication request is similarly sent with certificate verification disabled:

python
headers = {
    'Accept': 'application/json',
    'Content-Type': C
...[truncated 4119 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for IAM, OBS, and GES endpoints. Reject an iam_url or service URL whose scheme is not https:.
  2. Remove every verify=False argument from Python requests and do not globally suppress InsecureRequestWarning.
  3. Remove rejectUnauthorized: false from Node.js request options.
  4. Use the operating system's trusted CA store by default. If a private GES deployment uses an internal CA, accept an explicit CA bundle path rather than disabling validation.
  5. Make the GES scheme configurable but secure by default, and reject plaintext HTTP outside a separately enabled, clearly documented local-development mode.
  6. Apply strict hostname validation and avoid automatically following authentication requests to unrelated hosts.
  7. Add automated tests that confirm invalid, expired, and hostname-mismatched certificates are rejected.
  8. Rotate any credentials or tokens that have previously traversed an untrusted network using the vulnerable implementation.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ges_graph_skill.py:1194
Finding

Full graph deletion APIs do not enforce the documented confirmation requirement

Content
View full analysis

Vulnerability Details

File Location: scripts/ges_graph_skill.py:1194-1210; scripts/ges_graph_skill.js:897-903; safety requirement documented at SKILL.md:116-123
Vulnerability Type: Unguarded destructive operation
Risk Level: High

Technical Analysis

The Python client exports a graph-clearing method that immediately issues either the dedicated clear API request or an unconditional Cypher deletion:

python
def clear_graph(self, use_api: bool = True) -> Dict:
    """清空图中所有数据

    Args:
        use_api: 是否使用专用API方式(默认True)。若为False,则使用Cypher方式.

    Returns:
        执行结果,包含job_id(API方式)或查询结果(Cypher方式)
    """
    if use_api:
        # 使用专用clear-graph API,更彻底
        return self._request('POST', '/action?action_id=clear-graph', json={})
    else:
        # 备用Cypher方式
        statement = "MATCH (n) DETACH DELETE n"
        return self.execute_cypher(statement)

The JavaScript implementation exposes the same unguarded behavior:

javascript
async clearGraph(useApi = true) {
    if (useApi) {
        return this._request('POST', '/action?action_id=clear-graph', {});
    } else {
        const statement = "MATCH (n) DETACH DELETE n";
        return this.executeCypher(statement);
    }
}

SKILL.md states that clearing all graph data requires explicit confirmation, but this requirement exists only as an Agent instruction. Neither executable implementation accepts a confirmation value, validates the selected graph, provides a dry-run, nor performs an interactive confirmation.

Consequently, any Agent workflow or other local caller with access to the exported client and configured credentials can invoke the destructive operation directly. The default argument selects the dedicated clear API, so no optional safety setting must be disabled first.

Attack Path

  1. The Skill is configured with credentials that authorize mutation of a GES graph.
  2. An Agent workflow or another caller imports the exported GESClient.
  3. The caller invok ...[truncated 1272 chars]
Remediation
View remediation

Remediation Suggestions

  1. Enforce confirmation inside both clear_graph and clearGraph; do not rely solely on instructions in SKILL.md.
  2. Require a confirmation value bound to the exact target, such as the project ID and graph name. Reject generic booleans or a reusable global "confirm" value.
  3. Use a two-step design:
    • First return the target graph identity, node and edge counts, and a short-lived operation nonce.
    • Then require the caller to submit that nonce and the exact graph name to execute deletion.
  4. Add a dry-run mode that is the default and reports the deletion scope without changing data.
  5. Require a separate explicit option for the Cypher fallback so it cannot silently bypass the dedicated API's safeguards.
  6. Log the authenticated identity, target graph, confirmation event, and operation ID without recording credentials or bearer tokens.
  7. Add tests proving that calls without confirmation, with stale confirmation, or with confirmation for another graph are rejected.
  8. Recommend and verify a recent backup before issuing the destructive request where the service supports backup validation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is described as an access guide, but the content clearly enables active execution of authenticated graph, import/export, and storage operations using cloud credentials. This mismatch is dangerous because users or orchestration systems may treat it as passive documentation while it actually supports state-changing and data-moving actions, including destructive operations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
> - Query scripts are located under the skill directory `scripts/` (e.g., `scripts/ges_graph_skill.py`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
> - Query scripts are located under the skill directory `scripts/` (e.g., `scripts/ges_graph_skill.py`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- `ges_graph_skill.js` - Node.js SDK for GES graph operations

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
- `ges_graph_skill.js` - Node.js SDK for GES graph operations

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The documentation explicitly states that access_key and secret_key are automatically read from .env for export operations, confirming credential access by the skill. Even if secrets are not printed, automatic loading of cloud credentials materially raises risk because execution-capable examples can perform authenticated external operations and make accidental or unauthorized data export easier.

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

md
edge_path="obs://bucket/edge"
)

# Export graph data (access_key/secret_key are read from .env automatically)
job_id = skill.client.export_graph(
    export_path="obs://bucket/export",
    vertex_set_name="set_vertex",

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The skill is designed to access credential-bearing local configuration under .env and combine it with environment variables to authenticate to cloud services. In an agent-executed skill, direct secret access is a genuine credential-exposure risk because it broadens what sensitive material the skill can consume and use without strong isolation or least-privilege controls.

Content

Scanner excerpt · scripts/ges_graph_skill.js (reported line 18)May include surrounding context.

js
// ==================== 环境配置 ====================

class EnvConfig {
    static ENV_DIR = path.join(__dirname, '..', '.env');

    static ENV_VAR_MAPPING = {
        'GES_GRAPH_IP': 'graph_ip',

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/ges_graph_skill.js (reported line 463)May include surrounding context.

js
const contents = [];
        const regex = /<Contents><Key>([^<]+)<\/Key><LastModified>([^<]+)<\/LastModified><ETag>([^<]+)<\/ETag><Size>(\d+)<\/Size>/g;
        let match;
        while ((match = regex.exec(result.body)) !== null) {
            contents.push({
                Key: match[1],
                LastModified: match[2],

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The node-deletion capability performs irreversible graph modifications without any built-in warning, dry-run, or confirmation mechanism. In a graph administration skill, silent destructive primitives are particularly dangerous because a mistaken call or prompt injection could delete production data immediately.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill exposes a whole-graph clear operation that can wipe all data through either an API call or a bulk Cypher delete, with no confirmation or safety interlock. In context, this is more dangerous than a generic admin helper because the skill is intended for terminal-driven use where a single mistaken invocation can cause catastrophic data loss.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ges_graph_skill.py (reported line 27)May include surrounding context.

python
class EnvConfig:
    """环境配置管理 - 支持环境变量和配置文件读取"""

    ENV_DIR = os.path.join(SKILL_DIR, '.env')

    ENV_VAR_MAPPING = {
        'GES_GRAPH_IP': 'graph_ip',

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description focuses on GES graph operations, but the code also implements direct OBS object-storage access including upload, download, listing, and deletion. Hidden storage access expands the skill's privileges beyond user expectations and can enable unintended data movement or tampering.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Standalone object-storage manipulation is a materially different capability from providing GES guidance, especially when it supports arbitrary object upload, download, and deletion. In an agent environment, this unjustified breadth can be abused to exfiltrate, overwrite, or destroy cloud-hosted data unrelated to graph operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as an access guide for operating Huawei Cloud GES via terminal, but it includes destructive mutation capabilities such as graph clearing and broad write operations. In an agent setting, this mismatch increases the chance that a user or upstream system invokes data-destructive actions without understanding the true blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The clear_graph method can remove all graph data, including via a dedicated clear-graph API, but provides no built-in confirmation or guardrails. In a terminal/agent context this is highly dangerous because a single prompt or mistaken tool invocation can cause complete data loss.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents executable behavior that reads environment variables and files and performs networked operations, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent or reviewer may underestimate the skill's ability to access credentials and make outbound requests, increasing the chance of unintended or over-privileged execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list is broad enough to match many generic graph-database requests, even when the user may only want conceptual help. Overbroad activation can cause an execution-capable skill with credential and network access to be selected in situations where a safer, read-only response would be more appropriate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that direct API calls are prohibited, yet later instructs users to use the underlying request API directly for GQL execution. Contradictory safety instructions weaken guardrails, making it easier for agents or users to bypass intended wrappers and any validation or confirmation logic they might enforce.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation claims graph-wide destructive actions require explicit confirmation, but it presents graph-clearing functionality as a normal callable operation without showing any confirmation or enforcement mechanism. This inconsistency can lead an agent to invoke irreversible deletion based on examples alone, especially in automated settings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents import/export operations involving OBS paths without prominently warning that these actions can move large volumes of data across services and trust boundaries. In practice, that can enable unintended exfiltration, replication, or cost-generating transfers if an agent treats them as routine examples.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code automatically reads credentials and configuration from local files and environment variables, including passwords and cloud keys, without an explicit user-mediated trust boundary. In an agent-skill context, silent access to local secrets is sensitive because it enables privileged cloud actions beyond what a user may realize the skill is doing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reads sensitive credentials such as passwords, access keys, and secret keys from environment/config sources without any user-facing notice or consent flow. In an agent setting, undisclosed secret consumption is risky because it can surprise users and facilitate unintended privileged operations against external services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill implements full OBS object-storage capabilities including listing, upload, download, and deletion, which materially exceeds the stated GES graph-terminal access scope. This scope expansion increases the blast radius: a caller expecting graph operations could unintentionally or indirectly gain file exfiltration and destructive storage capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The OBS methods can upload local files, download remote objects to local paths, and delete remote objects, but the code provides no user-facing warning about data transfer, local file writes, or remote deletion. This creates a real risk of unintended exfiltration, overwriting local files, or destructive changes to cloud storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill’s primary natural-language description is written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ges_graph_skill.js:603

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ges_graph_skill.py:179