Back to skill

Security audit

huawei-cloud-iam-manage

Security checks for vulnerabilities and agentic risk

Overview

This Huawei IAM admin skill is mostly coherent, but it needs review because it can make high-impact cloud identity changes and also installs a remote telemetry CLI persistently into the user environment.

Install only if you intend to let the agent manage Huawei Cloud IAM resources with the permissions of your configured hcloud profile. Review the telemetry CLI installation first, consider installing dependencies manually with pinned checksums, avoid running the PATH-persisting installer unless you accept shell profile changes, and handle password/AK/SK operations in a sandbox or least-privilege account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on Huawei Cloud IAM lifecycle management actions and safety-guarded write operations. The actual code chunk does not interact with Huawei IAM resources at all: it neither lists nor creates/deletes users, groups, policies, agencies, nor manages access keys. Instead, its sole purpose is bootstrapping a local CLI dependency by checking for skill-quality-cli, downloading it if missing, copying binaries into ~/.local/bin, and persisting PATH updates in user shell config files. These behaviors are materially different from the declared IAM management purpose and introduce undeclared capabilities involving local environment modification and remote software installation. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is a write-capable Huawei Cloud IAM administration skill with 20 specific IAM actions and safety controls around destructive or sensitive identity operations. The actual code does none of that. It only installs a local utility named skill-quality-cli by querying a version API, downloading an archive, copying files into ~/.local/bin, changing permissions, and editing ~/.bashrc and ~/.profile to add PATH entries. This is a materially different primary purpose and involves different resources (local filesystem, shell config, remote artifact endpoints) than the declared IAM management scope. This is not a supporting implementation detail for IAM behavior; it is unrelated installer functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs behavior unrelated to Huawei Cloud IAM management by downloading, installing, and persisting a separate global CLI in the user's environment. This expands the skill's trust boundary, creates a supply-chain risk, and gives the package ongoing influence over future shell sessions through PATH modification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script modifies the local environment by exporting PATH and appending to ~/.bashrc and ~/.profile, which is outside the stated IAM-management purpose of the skill. Because this creates persistent system changes, the skill can affect unrelated future commands and establish a foothold beyond the immediate task.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 15)May include surrounding context.

sh
PATH 兜底与持久化,兼容非 login shell)

# 0. PATH 兜底: 安装目录 ~/.local/bin 可能不在 PATH 中(非 login shell 下 `command -v` 会 miss)。
#    启动即导出到当前会话, 并幂等持久化到 ~/.bashrc / ~/.profile。
case ":$PATH:" in
  *":$HOME/.local/bin:"*) ;;
  *) export PATH="$HOME/.local/bin:$PATH" ;;
esac
if ! grep -qsF '$HOME/.local/bin' ~/.bashrc; then
    echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
fi
if ! grep -qsF '$HOME/.local/bin' ~/.profile; then
    echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.profile
fi

# 1. 已安装且可用 → 退出(优先 PATH, 兜底 ~/.local/bin 绝对路径)
CLI_BIN="$(command -v skill-quality-cli 2>/dev/null || true)"
if [ -z "$CLI_BIN" ] && [ -x "$HOME/.local/bin/skill-quality-cli" ]; then
    CLI_BIN="$HOME/.local/bin/skill-quality-cli"
fi
if [ -n "$CLI_BIN" ] && "$CLI_BIN" version >/dev/null 2>&1; then
    exit 0
fi

# 2. 未安装 → 执行安装(幂等; 载体=全局 CLI; 失败静�

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/install_cli.sh (reported line 17)May include surrounding context.

sh
PATH 兜底与持久化,兼容非 login shell)

# 0. PATH 兜底: 安装目录 ~/.local/bin 可能不在 PATH 中(非 login shell 下 `command -v` 会 miss)。
#    启动即导出到当前会话, 并幂等持久化到 ~/.bashrc / ~/.profile。
case ":$PATH:" in
  *":$HOME/.local/bin:"*) ;;
  *) export PATH="$HOME/.local/bin:$PATH" ;;
esac
if ! grep -qsF '$HOME/.local/bin' ~/.bashrc; then
    echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
fi
if ! grep -qsF '$HOME/.local/bin' ~/.profile; then
    echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.profile
fi

# 1. 已安装且可用 → 退出(优先 PATH, 兜底 ~/.local/bin 绝对路径)
CLI_BIN="$(command -v skill-quality-cli 2>/dev/null || true)"
if [ -z "$CLI_BIN" ] && [ -x "$HOME/.local/bin/skill-quality-cli" ]; then
    CLI_BIN="$HOME/.local/bin/skill-quality-cli"
fi
if [ -n "$CLI_BIN" ] && "$CLI_BIN" version >/dev/null 2>&1; then
    exit 0
fi

# 2. 未安装 → 执行安装(幂等; 载体=全局 CLI; 失败静�

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The script retrieves version metadata from a remote endpoint and then downloads a tarball for installation, but it does not verify a pinned checksum, signature, or trusted immutable version. This creates a supply-chain exposure where a compromised endpoint, bucket, or network path could cause execution of attacker-controlled binaries.

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 34)May include surrounding context.

sh
API_URL="https://skillsapi.developer.myhuaweicloud.com/api/quality/cli/latest"
OBS_BASE="https://obs-skills-repository.obs.cn-north-4.myhuaweicloud.com/skill-quality-cli"

V=$(curl -s "${API_URL}" | python3 -c 'import sys,json;print(json.load(sys.stdin)["version"])' 2>/dev/null)
if [ -z "$V" ]; then
    echo "警告: 无法获取 skill-quality-cli 最新版本,跳过安装" >&2
    exit 0

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer fetches and installs a separate 'skill-quality-cli' component that is not part of the IAM-management capability described in the skill metadata. This creates unnecessary supply-chain and trust expansion: a user invoking an IAM skill may unknowingly install extra executable code into their environment, including persistent binaries and Python helper files, without integrity verification beyond HTTPS.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The script retrieves version metadata from a remote API and then uses that unpinned value to download and install an executable tarball. This is dangerous because the installed code is determined at runtime by an external service, with no signature or checksum verification, making the flow susceptible to supply-chain compromise, malicious server-side changes, or unexpected version substitution.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 26)May include surrounding context.

sh
API_URL="https://skillsapi.developer.myhuaweicloud.com/api/quality/cli/latest"
OBS_BASE="https://obs-skills-repository.obs.cn-north-4.myhuaweicloud.com/skill-quality-cli"

V=$(curl -s "${API_URL}" | python3 -c 'import sys,json;print(json.load(sys.stdin)["version"])' 2>/dev/null)
if [ -z "$V" ]; then
    echo "无法获取 skill-quality-cli 最新版本" >&2
    exit 1

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs use of shell commands (hcloud, skill-quality-cli, shell redirection, temp files), yet it declares no explicit tool scope or allowed-tools boundary. Missing tool scoping increases the chance the runtime grants broader execution than intended or that reviewers cannot accurately assess what the skill is permitted to do.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad generic terms such as IAM, policy, identity, delete, and create user, which can cause the write-capable skill to activate in contexts beyond the user's actual intent. Because this skill can manage identities, policies, agencies, and credentials, accidental activation materially raises the risk of unintended privileged operations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
| Capability | Risk level | Actions |
| ---------- | ---------- | ------- |
| Query (read-only pre-checks) | R3 — auto execute | `huawei_list_iam_users`, `huawei_list_iam_groups`, `huawei_list_iam_policies`, `huawei_list_iam_agencies`, `huawei_list_iam_custom_policies` |
| Diagnose / Analyze (read-only) | R3 — auto execute | `huawei_analyze_iam_least_privilege`, `huawei_analyze_iam_password_compliance` |
| Manage (create/configure) | R2 — preview + confirm | `huawei_create_iam_user`, `huawei_create_iam_group`, `huawei_attach_iam_policy`, `huawei_detach_iam_policy`, `huawei_create_iam_agency`, `huawei_create_iam_ak_sk`, `huawei_create_iam_custom_policy`, `huawei_config_iam_login` |
| Manage (delete) | R1 — preview + confirm + impact list | `huawei_delete_iam_user`, `huawei_delete_iam_group`, `huawei_delete_iam_agency`, `huawei_delete_iam_ak_sk`, `huawei_delete_iam_custom_policy` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| Capability | Risk level | Actions |
| ---------- | ---------- | ------- |
| Query (read-only pre-checks) | R3 — auto execute | `huawei_list_iam_users`, `huawei_list_iam_groups`, `huawei_list_iam_policies`, `huawei_list_iam_agencies`, `huawei_list_iam_custom_policies` |
| Diagnose / Analyze (read-only) | R3 — auto execute | `huawei_analyze_iam_least_privilege`, `huawei_analyze_iam_password_compliance` |
| Manage (create/configure) | R2 — preview + confirm | `huawei_create_iam_user`, `huawei_create_iam_group`, `huawei_attach_iam_policy`, `huawei_detach_iam_policy`, `huawei_create_iam_agency`, `huawei_create_iam_ak_sk`, `huawei_create_iam_custom_policy`, `huawei_config_iam_login` |
| Manage (delete) | R1 — preview + confirm + impact list | `huawei_delete_iam_user`, `huawei_delete_iam_group`, `huawei_delete_iam_agency`, `huawei_delete_iam_ak_sk`, `huawei_delete_iam_custom_policy` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
| Capability | Risk level | Actions |
| ---------- | ---------- | ------- |
| Query (read-only pre-checks) | R3 — auto execute | `huawei_list_iam_users`, `huawei_list_iam_groups`, `huawei_list_iam_policies`, `huawei_list_iam_agencies`, `huawei_list_iam_custom_policies` |
| Diagnose / Analyze (read-only) | R3 — auto execute | `huawei_analyze_iam_least_privilege`, `huawei_analyze_iam_password_compliance` |
| Manage (create/configure) | R2 — preview + confirm | `huawei_create_iam_user`, `huawei_create_iam_group`, `huawei_attach_iam_policy`, `huawei_detach_iam_policy`, `huawei_create_iam_agency`, `huawei_create_iam_ak_sk`, `huawei_create_iam_custom_policy`, `huawei_config_iam_login` |
| Manage (delete) | R1 — preview + confirm + impact list | `huawei_delete_iam_user`, `huawei_delete_iam_group`, `huawei_delete_iam_agency`, `huawei_delete_iam_ak_sk`, `huawei_delete_iam_custom_policy` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
| Capability | Risk level | Actions |
| ---------- | ---------- | ------- |
| Query (read-only pre-checks) | R3 — auto execute | `huawei_list_iam_users`, `huawei_list_iam_groups`, `huawei_list_iam_policies`, `huawei_list_iam_agencies`, `huawei_list_iam_custom_policies` |
| Diagnose / Analyze (read-only) | R3 — auto execute | `huawei_analyze_iam_least_privilege`, `huawei_analyze_iam_password_compliance` |
| Manage (create/configure) | R2 — preview + confirm | `huawei_create_iam_user`, `huawei_create_iam_group`, `huawei_attach_iam_policy`, `huawei_detach_iam_policy`, `huawei_create_iam_agency`, `huawei_create_iam_ak_sk`, `huawei_create_iam_custom_policy`, `huawei_config_iam_login` |
| Manage (delete) | R1 — preview + confirm + impact list | `huawei_delete_iam_user`, `huawei_delete_iam_group`, `huawei_delete_iam_agency`, `huawei_delete_iam_ak_sk`, `huawei_delete_iam_custom_policy` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
| Capability | Risk level | Actions |
| ---------- | ---------- | ------- |
| Query (read-only pre-checks) | R3 — auto execute | `huawei_list_iam_users`, `huawei_list_iam_groups`, `huawei_list_iam_policies`, `huawei_list_iam_agencies`, `huawei_list_iam_custom_policies` |
| Diagnose / Analyze (read-only) | R3 — auto execute | `huawei_analyze_iam_least_privilege`, `huawei_analyze_iam_password_compliance` |
| Manage (create/configure) | R2 — preview + confirm | `huawei_create_iam_user`, `huawei_create_iam_group`, `huawei_attach_iam_policy`, `huawei_detach_iam_policy`, `huawei_create_iam_agency`, `huawei_create_iam_ak_sk`, `huawei_create_iam_custom_policy`, `huawei_config_iam_login` |
| Manage (delete) | R1 — preview + confirm + impact list | `huawei_delete_iam_user`, `huawei_delete_iam_group`, `huawei_delete_iam_agency`, `huawei_delete_iam_ak_sk`, `huawei_delete_iam_custom_policy` |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states password-bearing jsonInput files are temporary and immediately removed, but the example commands create /tmp/login_profile.json and /tmp/update_login_profile.json without any deletion step. This can leave plaintext passwords on disk where other local users, backups, or forensic processes may recover them.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 573)May include surrounding context.

md
## Security Considerations

- MUST always pre-check with read-only list commands before write actions (avoid duplicate/incorrect targets).
- MUST show the full command and ask for confirmation for every R2/R1 action — never auto-execute writes.
- MUST enumerate impacted resources and show the irreversible warning for R1 deletes.
- MUST print the high-authority warning when attaching an admin/full-access policy.
- MUST print the cross-account warning when creating an agency for an external account.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
## 2. Behavior

- [ ] Query/Diagnose (R3) actions execute **automatically** without confirmation.
- [ ] Manage (R2/R1) actions always show a **preview + explicit confirmation**; R1 deletes additionally
      enumerate the impacted resources (user's AK/SK, group memberships, attached policies; agency
      policies; policy attachments).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 21)May include surrounding context.

md
## 2. Behavior

- [ ] Query/Diagnose (R3) actions execute **automatically** without confirmation.
- [ ] Manage (R2/R1) actions always show a **preview + explicit confirmation**; R1 deletes additionally
      enumerate the impacted resources (user's AK/SK, group memberships, attached policies; agency
      policies; policy attachments).

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 28)May include surrounding context.

&& echo "SHA-256 verified" || { echo "SHA-256 MISMATCH - abort"; exit 1; }

3) Unpack and install into a user-local directory

mkdir -p ~/.local/hcloud && tar -zxf KooCLI-linux-amd64.tar.gz -C ~/.local/hcloud export PATH="$HOME/.local/hcloud:$PATH"

text

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The guide uses huaweicloud/cloud-cli:latest, which is mutable and can change over time without review. This weakens supply-chain integrity and reproducibility: users may pull a newer or compromised image than the one originally validated, and the container runs an authenticated cloud-management CLI capable of sensitive IAM actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file states that command execution quality telemetry is reported through skill-quality-cli and describes a mandatory wrapper, but it does not clearly disclose what data is collected, whether command arguments/output may be transmitted, where it is sent, or how sensitive IAM-related metadata is protected. In a skill that manages identities, policies, agencies, and AK/SK workflows, unclear telemetry behavior increases the risk of inadvertent leakage of operationally sensitive information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The comments describe the installer as silent and non-blocking, but the script emits warnings/output and makes persistent profile changes. This discrepancy can mislead reviewers and users about the true side effects, reducing informed consent and increasing the chance the behavior is overlooked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script appends to ~/.bashrc and ~/.profile without prompting the user or requiring explicit confirmation. Silent persistence into shell startup files is risky because it changes future execution environments and is commonly abused for unwanted or deceptive post-install behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.