Back to skill

Security audit

huawei-cloud-iam-query

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a read-only Huawei Cloud IAM query skill, but it needs Review because its setup and authenticated cloud calls disable TLS checks and can execute downloaded installer code.

Review before installing. Use only least-privilege, preferably temporary Huawei Cloud credentials; do not run this on untrusted networks or through untrusted proxies. The publisher should restore TLS verification, remove the get-pip download-and-execute fallback, pin or verify dependencies, and make the documented scope consistently IAM-only.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/ensure_env.py:28
Finding

Remote Python bootstrap is downloaded and executed without TLS verification

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py:28, 279-295
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: High

Vulnerable code:

python
ssl._create_default_https_context = ssl._create_unverified_context
python
get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py")
urls = [
    "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py",
    "https://bootstrap.pypa.io/get-pip.py",
]

ctx = ssl._create_unverified_context()

for url in urls:
    info(f"尝试下载 get-pip.py: {url}")
    try:
        urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    except Exception as e:
        print(f"    下载失败: {e}")
        continue

    rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)
    if rc == 0:
        ok("get-pip.py 安装 pip 成功")
        return True

Technical Analysis

The mandatory environment-preparation flow invokes _ensure_pip() when pip is unavailable. If the local ensurepip bootstrap also fails, the function downloads get-pip.py from an external URL and executes it with the current Python interpreter.

Both the process-wide HTTPS context and the download-specific context disable certificate validation. The downloaded file is not authenticated using a pinned cryptographic hash or digital signature before execution. Consequently, HTTPS no longer establishes the identity of the remote server.

This behavior crosses a network-to-code-execution trust boundary: bytes supplied over an unauthenticated network channel become executable Python code. The Skill requires Huawei Cloud credentials to be present in environment variables before this setup flow succeeds, so injected code would execute in a process environment containing HW_ACCESS_KEY, HW_SECRET_KEY, and potentially HW_SECURITY_TOKEN.

Attack Path

  1. The user invokes the Skill, whose documented prerequisite ...[truncated 1357 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the process-wide assignment to ssl._create_default_https_context.
  2. Use Python’s default verified HTTPS context for all downloads.
  3. Do not create or pass ssl._create_unverified_context() to urlretrieve.
  4. Verify the downloaded bootstrap using a pinned SHA-256 digest or a trusted digital signature before execution.
  5. Download to a securely created, uniquely named temporary file and delete it after verification and execution.
  6. Prefer failing closed with manual installation instructions when ensurepip is unavailable rather than automatically executing remote bootstrap code.
  7. Run dependency setup before cloud credentials are placed in the process environment, reducing credential exposure if bootstrap execution is compromised.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:8
Finding

TLS certificate verification is disabled for authenticated Huawei Cloud IAM requests

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py:8-9, 44-54
Vulnerability Type: Improper certificate validation
Risk Level: Medium

Vulnerable code:

python
# Suppress warnings caused by ignore_ssl_verification
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
python
def build_http_config():
    """Build HTTP configuration with environment-variable proxy support."""
    http_config = HttpConfig.get_default_config()
    http_config.ignore_ssl_verification = True
    http_config.timeout = (30, 60)
    http_config.retry_times = 3

    proxy_url = _get_proxy_url()
    if proxy_url:
        parsed = urlparse(proxy_url)
        http_config.proxy_protocol = parsed.scheme or "http"
        http_config.proxy_host = parsed.hostname or ""
        http_config.proxy_port = parsed.port or 8080
        http_config.proxy_user = parsed.username or ""
        http_config.proxy_password = parsed.password or ""

    return http_config

Technical Analysis

build_http_config() is imported by the IAM scripts and by the credential-validation path. It unconditionally sets ignore_ssl_verification to True, causing the Huawei Cloud SDK to accept server certificates that are expired, self-signed, issued for another hostname, or signed by an untrusted authority. The module also globally suppresses the warning that would otherwise reveal this unsafe mode.

The query scripts then attach the user’s Huawei Cloud credentials to clients configured with this HTTP configuration. For example, scripts/iam/list_users_v5.py calls build_http_config(), supplies AK/SK-based credentials to the client builder, and invokes client.list_users_v5(request). Therefore, the flaw applies to authenticated IAM traffic rather than only to an unauthenticated connectivity test.

Request signing may prevent straightforward recovery of the secret key from a captured request, but it does not r ...[truncated 1725 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove http_config.ignore_ssl_verification = True and retain certificate verification by default.
  2. Remove global suppression of InsecureRequestWarning.
  3. For organizations using a TLS-inspecting proxy or private certificate authority, support an explicit CA bundle path rather than disabling verification.
  4. Validate proxy configuration and document that proxy operators can observe connection metadata.
  5. Fail closed when certificate or hostname validation fails.
  6. Add regression tests confirming that self-signed, expired, hostname-mismatched, and untrusted certificates are rejected.
  7. Apply the corrected configuration to both normal IAM query clients and the credential-validation client.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill may create virtual environments, install or upgrade packages, invoke system package managers, download bootstrap scripts, and even disable SSL verification, none of which are consistent with a read-only IAM query claim. Those behaviors materially expand the attack surface to supply-chain compromise, local host modification, credential exposure, and man-in-the-middle risks under the guise of benign cloud inspection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill may create virtual environments, install or upgrade packages, invoke system package managers, download bootstrap scripts, and even disable SSL verification, none of which are consistent with a read-only IAM query claim. Those behaviors materially expand the attack surface to supply-chain compromise, local host modification, credential exposure, and man-in-the-middle risks under the guise of benign cloud inspection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill may create virtual environments, install or upgrade packages, invoke system package managers, download bootstrap scripts, and even disable SSL verification, none of which are consistent with a read-only IAM query claim. Those behaviors materially expand the attack surface to supply-chain compromise, local host modification, credential exposure, and man-in-the-middle risks under the guise of benign cloud inspection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill may create virtual environments, install or upgrade packages, invoke system package managers, download bootstrap scripts, and even disable SSL verification, none of which are consistent with a read-only IAM query claim. Those behaviors materially expand the attack surface to supply-chain compromise, local host modification, credential exposure, and man-in-the-middle risks under the guise of benign cloud inspection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill may create virtual environments, install or upgrade packages, invoke system package managers, download bootstrap scripts, and even disable SSL verification, none of which are consistent with a read-only IAM query claim. Those behaviors materially expand the attack surface to supply-chain compromise, local host modification, credential exposure, and man-in-the-middle risks under the guise of benign cloud inspection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises an IAM-only query skill, but the body describes a generic Huawei Cloud resource-enumeration framework covering images, disks, VPC-related dependencies, and other non-IAM services. That inconsistency is dangerous because it can mislead approval and routing systems into granting a broadly enumerative cloud skill under a narrow IAM label, enabling unintended access to a much wider set of cloud metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented capability scope explicitly expands into multi-service resource listing and dependency mapping, which exceeds the stated IAM identity-query purpose. In a cloud environment, broad enumeration can expose infrastructure topology, resource identifiers, and dependency data useful for lateral movement, reconnaissance, or targeted abuse if an attacker can invoke the skill.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云资源查询 - 环境检查前置脚本 (Windows PowerShell)
#>

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 69)May include surrounding context.

python
# 用 venv Python 重新执行当前脚本
    print(f"  使用虚拟环境 Python: {venv_python}")
    os.execv(venv_python, [venv_python] + sys.argv)

def info(msg):
    print(f"  {msg}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code invokes system package managers and installer commands, potentially with elevated privileges, despite the skill being positioned as a read-only IAM query helper. This is dangerous because it can modify the host system, install software the user did not explicitly approve, and create a broad trust boundary around package sources and local package-manager configuration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script downloads get-pip.py from the network and executes it locally, while SSL verification has been globally disabled earlier in the file. That combination creates a serious supply-chain/code-execution risk: a network attacker or compromised mirror could deliver arbitrary Python code, which the script would run on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Downloading and executing get-pip.py without a prominent warning or explicit consent is unsafe, especially since it results in immediate code execution from the network. The risk is amplified here by the script's role mismatch and disabled TLS verification elsewhere in the file.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs the agent to execute shell commands, inspect environment variables, and access the network, but it does not declare any explicit tool scope such as allowed-tools or permissions. This weakens policy enforcement and makes it harder to constrain execution to the minimum necessary privileges, increasing the chance of over-broad command execution or unintended access to secrets and external services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad generic terms such as identity and policy, which can cause accidental invocation in unrelated contexts. Because this skill performs command execution, environment checks, and cloud queries, overly broad triggering increases the risk of unnecessary credential use, unintended reconnaissance, or invocation of a more powerful skill than the user expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and body describe a general Huawei Cloud resource query skill, while the manifest positions it as IAM-specific. This inconsistency undermines trust boundaries and can cause operators or automated systems to invoke or approve the skill under false assumptions about what resources it can access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Directing the agent to use arbitrary service-category scripts under scripts// and references// suggests a generic execution framework rather than a narrowly bounded IAM tool. Even if intended for convenience, this pattern increases the chance of invoking unintended scripts or hidden capabilities beyond the reviewed manifest scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide explicitly documents read-only commands that enumerate sensitive IAM authentication material and security state, including AK/SK inventory, last-use data, MFA devices, and login-related protections, but provides no warning about sensitivity, least-privilege use, or output handling. In an IAM-query skill, this is not inherently malicious, but it increases the risk of credential exposure, account reconnaissance, and unsafe disclosure of high-value identity metadata to users, logs, or downstream systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This PowerShell script presents all user-facing messages in Chinese, including status, failure, and remediation text. Because the file contains no opt-in, fallback, or justification for a Chinese-only locale, it creates a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 40)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 187)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 188)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ensure_env.py:284