Back to skill

Security audit

huawei-cloud-iam-diagnose

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Huawei IAM read-only diagnostic tool, but it can auto-run sensitive account enumeration and install extra local tooling with unclear telemetry details.

Install only if you are comfortable with an agent reading Huawei Cloud IAM structure using your configured credentials and with the setup scripts installing local dependencies or the optional telemetry CLI. Use a least-privilege read-only IAM identity, avoid pasting AK/SK into chat, consider setting SKILL_QUALITY_REPORT=0, and run the scripts manually rather than relying on broad auto-execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (60)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described OBS download, checksum verification, local binary installation, and permission changes are installer behaviors rather than IAM analysis behaviors. Even if well-intended, bundling them into a diagnostic skill expands the attack surface and can mislead users about what actions will be performed on the host.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 14)May include surrounding context.

bash
# Linux x86_64 —— 官方离线包(下载 → 校验 SHA256 → 解压,不执行远程脚本)
# 1) 下载官方归档包与校验文件
curl -sSfL -o /tmp/hcloud.tar.gz https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz
curl -sSfL -o /tmp/hcloud.tar.gz.sha256 https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz.sha256
# 2) 校验一致性后再解压安装
echo "$(cat /tmp/hcloud.tar.gz.sha256)  /tmp/hcloud.tar.gz" | sha256sum -c -

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云IAM参考性权限分析 - 环境检查前置脚本 (Windows PowerShell)
#>

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script can invoke winget, apt, yum, dnf, and potentially sudo-driven package installation on the host. For a skill whose purpose is IAM permission diagnosis, this is over-privileged behavior that can alter the host system, install software, and create a large supply-chain and privilege-escalation attack surface if triggered unexpectedly or in automated environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script downloads get-pip.py from external URLs and executes it locally, which is a classic remote code execution and supply-chain risk. Even over HTTPS, executing fetched bootstrap code is dangerous, and it is especially unjustified in a read-only IAM analysis skill where host mutation and arbitrary code execution are out of scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares executable/networked behavior but does not define an explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where an agent may grant broader access than users expect, especially because the document also instructs shell execution, environment inspection, file access, and cloud/network operations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Marking the skill as auto-execute is risky because it can trigger read-access cloud queries, local shell commands, and possibly setup/telemetry steps without an explicit user confirmation gate. In an IAM context, even read-only automation can disclose sensitive account structure, usernames, groups, agencies, and policy relationships.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
attached policies + user-group inheritance + agencies), parses policy document Allow/Deny
  statements and outputs a "大概率有权限/无权限" reference verdict with a confidence grade and full
  chain trace. Group/agency permissions are cross-validated with the real IAM check interfaces.
  Read-only, R3 auto-execute. Honest boundary: no user-level policy-simulation API exists on
  Huawei Cloud, so results are reference-only, never an authoritative auth decision; custom policy
  + Condition + agency-stacking are flagged "仅供参考".
  Triggers include: 权限分析, 权限诊断, 权限评估, 是否有权限, 查权限, IAM 权限, 权限链路, 谁能访问,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains broad terms like 'has permission', 'who has access', and generic permission-diagnosis phrases, which can cause the skill to auto-activate in ordinary conversations outside the intended Huawei Cloud IAM context. Because the skill is marked auto-execute and can run shell/networked workflows, overbroad triggering materially increases accidental execution risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that telemetry is collected automatically but does not clearly disclose what data is sent, when it is sent, or whether command metadata, parameters, usernames, or cloud resource identifiers may leave the local environment. In a permission-analysis context, that omission can expose sensitive identity and infrastructure metadata without informed consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The repeated statement that all commands are auto-execute reinforces that operational commands may run without granular confirmation. Given the skill's ability to enumerate IAM relationships and potentially install/verify auxiliary tooling, this increases the chance of unintended execution and sensitive metadata exposure.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
## Core Commands

All commands below are read-only (R3, auto-execute). Paths are relative to the skill directory.

### Resolve user / list user groups (`huawei_list_user_groups`)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 30)May include surrounding context.

md
## 3. Read-only & R3

- [x] All 8 actions are read-only and R3 auto-execute (no write operations; no MFA confirmation gate).
- [x] Only IAM namespace scripts are used; no other skill is referenced.

## 4. Precision grading

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 30)May include surrounding context.

md
## 3. Read-only & R3

- [x] All 8 actions are read-only and R3 auto-execute (no write operations; no MFA confirmation gate).
- [x] Only IAM namespace scripts are used; no other skill is referenced.

## 4. Precision grading

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 55)May include surrounding context.

export HW_SECURITY_TOKEN=

text

**Never ask users to paste AK/SK into a chat.** Ask them to export the variables in their shell
profile and re-run.

## 3. Verify

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 92)May include surrounding context.

md
The CLI check commands (`KeystoneCheckProjectPermissionForGroup`,
`KeystoneCheckDomainPermissionForGroup`, `CheckProjectPermissionForAgency`, ...) return an
indistinguishable empty result and **exit code 0 for both HTTP 204 (has permission) and HTTP 404
(no permission)**. Do not use the CLI alone for a real yes/no verification — use
`scripts/check_group_permission.py` / `scripts/check_agency_permission.py`, which report the
actual HTTP status through the Python SDK.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/iam-policies.md (reported line 57)May include surrounding context.

text

> Grant the minimum that matches your environment. Do not grant `iam:*` unless strictly required,
> and never attach write actions (`create*`, `delete*`, `update*`, `associate*`, `detach*`) to a
> read-only diagnosis persona.

## 4. Notes

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring and CLI descriptions are written entirely in Chinese, and the script does not offer an English or locale-selectable alternative. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This PowerShell script presents its title, status messages, and remediation guidance entirely in Chinese. That creates a natural-language locale constraint for all users, and the file does not provide opt-in, fallback language handling, or any justification that the skill is intended only for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.