Back to skill

Security audit

huawei-cloud-icp-process-guidance

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Huawei Cloud ICP filing Q&A helper that mainly reads its bundled knowledge base and optionally uses disclosed web search for gaps.

Install this skill only if you want Chinese-language Huawei Cloud ICP filing guidance. Treat the web-search fallback as an external data flow, avoid putting identity numbers or account details in questions, and review the separate agent-reach dependency before enabling search.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill instructs the agent to read local files such as index.json and Markdown documents, which implies filesystem access, but it does not declare any explicit tool scope or permissions. This creates a mismatch between documented behavior and declared capabilities, weakening least-privilege controls and making it harder for reviewers or runtimes to constrain what the skill may access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as a bundled ICP knowledge-base Q&A tool, but later documents external web-search fallback behavior. This discrepancy can mislead operators and users about data flows and trust boundaries, causing sensitive user questions to be sent outside the local knowledge base unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill adds an external dependency and internet search capability through agent-reach/Exa even though its stated purpose is local ICP filing Q&A. Introducing networked dependencies expands the attack surface, creates supply-chain risk, and can expose user prompts or organizational context to third-party services without strong necessity or scoping.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fallback search design sends constructed queries to an external search provider but does not clearly warn users that their question content may leave the local environment. This creates a privacy and data-handling risk, especially if users include account details, case specifics, or internal operational context in their ICP-related questions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Using generic trigger terms like '问题' and '怎么办' can cause the skill to activate on unrelated conversations, increasing the chance that user content is processed under the wrong skill logic. In this skill, unintended activation matters more because the documented fallback may read local KB files and send queries to an external search provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown states that users of mainland China server nodes 'must' complete ICP filing and frames the topic as a general policy summary, but it does not clearly signal at the outset that the guidance is jurisdiction-specific to mainland China users. This can violate language/locale policy expectations because it imposes a region-specific policy without user opt-in or an explicit applicability gate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The embedded source content explicitly states that the filing platform supports Chinese-domain-name filing, and the entire procedure is written only in Chinese with no indication of language choice or opt-in. Under the policy, language or locale constraints should either offer user choice or be clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This procedure instructs users to prepare and upload highly sensitive materials such as identity documents, domain real-name verification details, signatures, and verification artifacts, but it does not include any warning or guidance about minimizing exposure, redacting unnecessary data, secure upload channels, retention, or phishing risk. In a document meant to operationalize document collection, that omission can lead users to overshare personal data or transmit it insecurely, increasing privacy and identity-fraud risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The procedure directs users to upload身份证件、授权书 and perform人脸/真实性核验, which involves highly sensitive personal data, but it does not explicitly warn users about handling, minimization, redaction limits, or verifying they are using the official Huawei Cloud filing interface. In a skill that operationally guides users through real-world compliance steps, omission of privacy and anti-phishing cautions can increase the chance that users disclose sensitive identity materials in an unsafe context or misunderstand what should only be submitted through trusted official channels.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document states that App-side claim/recognition filing steps exist and are consistent with the PC flow, but the cited source evidence only supports PC-side steps. In a procedural compliance skill, unsupported platform-specific guidance can mislead users into taking incorrect actions, causing filing delays, failed submissions, or reliance on nonexistent app functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The acceptance criterion says the skill activates 'when the user question matches trigger conditions' but does not define the trigger phrases, scope, or exclusion rules. This ambiguity can lead to unintended activation because reviewers cannot tell exactly which inputs should and should not invoke the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill is written as a mandatory Chinese-only operating procedure, including fixed Chinese query templates, disclaimer text, and output format, but it does not indicate that users may choose another language. Under the policy, a language/locale restriction is a violation unless the skill offers opt-in choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest describes a bundled ICP knowledge-base-only assistant, but this file explicitly permits live web search through Exa as a fallback. That expands the data boundary and trust model at runtime, creating a mismatch that can lead to unreviewed external content, prompt-injection exposure from search results, and policy drift beyond the declared scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description claims the skill is ready to use out of the box with its own knowledge base. Later sections state that external agent-reach installation is required for the search fallback path, which contradicts the implication of being fully self-contained for its documented behavior. This is a documentation-level intent mismatch rather than an implementation necessity issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document presents China ICP filing requirements and directs users to follow mainland regulatory and telecom authority rules throughout, but it does not explicitly state that the guidance is only for users operating within the PRC备案 context. Because the content is written as general advice under a broad FAQ/topic heading, it may impose a locale-specific policy framework without clear scope clarification or user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The prose claims '同一主体信息一次只能提交一个订单到管局审核' and attributes it to 'doc_0152#修改措施', but in the embedded source metadata for doc_0152 only a '驳回原因' section is listed at L202-L203 with no '修改措施' section. This is an intent/documentation inconsistency inside the knowledge file because the reference actively points to supporting material that the file itself does not provide.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown skill presents all user-facing guidance solely in Chinese and does not indicate that users can choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The requirement to always use a prescribed 'Briefing' format is a natural-language constraint on responses, but the document does not indicate user opt-in or explain why that format must always be enforced. While not a severe issue, it may conflict with organizational expectations if response style should adapt to user preference or context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Allowing retrieval of 'practical experience' from community/forums broadens the assistant from authoritative ICP guidance into informal third-party advice. In this context, that increases the chance of inaccurate or manipulated guidance being surfaced to users, especially for regulatory/compliance workflows where incorrect instructions can cause filing errors or data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file presents all verification instructions, test scenarios, and expected behaviors only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without documenting user choice or justified locale scope can be a language/locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring presents the script entirely in Chinese and describes it specifically as an ICP备案 knowledge-base indexing script, which signals a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in can be a natural-language policy concern when no alternative or choice is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.