Back to skill

Security audit

huawei-cloud-icp-rule-consult

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Huawei Cloud ICP filing advice skill, but its helper tools allow broader web and remote-browser access than the stated consultation purpose needs.

Review before installing. Use this only if you are comfortable granting the skill network access for documentation lookup, and avoid configuring remote Chrome unless it is an isolated browser with no sensitive sessions or internal-network reachability. A safer version would restrict fetch/search to approved Huawei Cloud documentation domains and keep normal TLS validation enabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The search tool is described as supporting generic keyword search and remote Chrome connectivity, while the skill is presented as a narrowly triggered备案 consultation flow. Without hard enforcement of intent restrictions, the browser/search capability can be used as general automation or retrieval infrastructure outside the intended domain, substantially increasing attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The search tool is described as supporting generic keyword search and remote Chrome connectivity, while the skill is presented as a narrowly triggered备案 consultation flow. Without hard enforcement of intent restrictions, the browser/search capability can be used as general automation or retrieval infrastructure outside the intended domain, substantially increasing attack surface.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
`SKILL.md` defines behavior; `references/catalog.yml` defines intent routing (triggers → entry_point → ontology_entities); `references/filing-rules.yml` defines

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents network-capable tooling and environment-dependent execution but does not declare an explicit tool/permission scope. That creates an authorization gap where the runtime may expose broader capabilities than the skill's stated read-only consultation purpose, increasing the chance of unintended network or environment access.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill instructs use of tools based on answer sufficiency but does not define strong security boundaries around when and where those tools may be used. In combination with network/browser capabilities, this creates effectively unrestricted operational latitude for external fetch/search actions, which can be abused if user input or linked references are adversarial.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
> **North Star** — Any assertion must be reducible to "rule × scope × document evidence"; irreducible assertions only list gaps, no conclusions.

- **Knowledge First** — Check embedded knowledge first, then fetch documents, then search. If embedded knowledge answers the question, do not invoke any tools.
- **Direct Mapping** — After matching a category, directly fetch the core document (URLs in `doc-commands.md`), do not search.
- **One Shot** — At most 1 round of follow-up question, must deliver an answer. If unclear, use the most common scenario + note supplementary points.
- **No Fabrication** — Do not propose solutions or workarounds not found in the knowledge base or fetched documents. If no documented solution exists, state the known constraints and provide the relevant document link, do not invent alternatives.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

Call-count limits reduce volume but do not meaningfully restrict what can be fetched or searched. A small number of unrestricted fetch/search operations is still sufficient for targeted access to unintended resources, especially given the generic retrieval and browser features described elsewhere in the skill.

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

md
3. **web_search + web_fetch combined ≤ 3 calls**
4. When category is directly matched, **prefer web_fetch on core document**, do not web_search
5. On single URL fetch failure, **retry at most once**, skip if still failing
6. **If embedded knowledge can answer, do not invoke any tools**

### Degradation

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is entirely in Chinese and does not indicate any user language choice or explicit justification that the skill is restricted to a Chinese-language audience. Under the language/locale policy, a skill should not implicitly force a specific language unless it offers opt-in or clearly documents the constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list for need_filing contains short, broadly phrased queries that can match normal conversational questions outside a clearly bounded ICP-consultation context. This can cause unintended routing to the skill, leading to inaccurate compliance guidance or bypass of the intended requirement that users explicitly ask about filing-related topics.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The access_filing triggers include context-free or highly colloquial phrases such as '过白' and '加白', which are ambiguous and may appear in unrelated support conversations. In a routing catalog, this increases accidental invocation risk and may misclassify general cloud support requests as ICP filing issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The account_subject_limit entry uses very generic phrases like '一个账号' and '多个主体', which are likely to overlap with ordinary account, IAM, or billing discussions. Because this skill is supposed to activate only for explicit filing-related requests, such broad triggers can incorrectly capture unrelated conversations and produce irrelevant regulatory guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The rule for vague questions allows the skill to activate on very generic inputs like “备案” or “备案咨询” without strong disambiguation. This can cause the agent to over-trigger on ambiguous user requests and provide domain-specific guidance when the user may not actually be asking for ICP filing help, weakening routing and boundary enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file states that entries are written in customer-service phrasing and directly answer questions in Chinese, with no indication that users may choose another language or locale. Because this is natural-language instruction content, it may impose a fixed language behavior without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file explicitly references activation-style user queries such as "备案咨询" and "备案" as examples of user inputs, but they are extremely broad and overlap with ordinary support requests. The document does not pair these examples with clear trigger boundaries or negative examples, which could lead a skill built from this knowledge base to activate on generic conversation about filing rather than specific ICP-beian intents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Accept-Language header is fixed to prefer zh-CN and zh, which imposes a specific language/locale behavior on all requests. This matches the policy category for language or locale constraints because the user is not given an opt-in or configuration mechanism, and the file does not clearly justify that all usage is region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file implements a general-purpose web fetcher that can retrieve HTML, extract text, and enumerate links from arbitrary URLs, which exceeds a narrowly scoped ICP-rule consultation skill. In an agent setting, this broad retrieval capability can be repurposed for unintended network access, including fetching unapproved external content or enabling SSRF-like behavior if user-controlled URLs are passed through.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI path accepts an arbitrary URL and dispatches it directly into network retrieval functions without any scope restriction tied to the skill's consultation-only purpose. In practice, this creates an unnecessary arbitrary URL fetch primitive that could be abused to access attacker-chosen hosts, making the skill more dangerous than its declared read-only ICP advisory function suggests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code can connect to an arbitrary remote Chrome instance via REMOTE_CHROME_HOST/CLI input and then drive that browser over CDP. In practice, this grants the skill access to whatever network reachability, session state, and browser context the remote instance has, which is unjustified for a read-only consultation skill and can enable SSRF-like internal browsing or abuse of privileged browser sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements a reusable browser-driven web search facility that accepts arbitrary keywords and a caller-controlled site parameter, which exceeds the narrowly declared scope of a read-only ICP filing consultation skill. In an agent setting, this expands the skill's reachable surface and can be repurposed to browse or scrape unrelated sites, undermining least-privilege and making prompt-driven misuse easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The browser context is created with ignore_https_errors=True, disabling TLS certificate validation for all navigations. This allows man-in-the-middle interception or redirection to spoofed support pages, which is especially risky because the tool is meant to provide authoritative compliance guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code unconditionally sets the Accept-Language header to prefer zh-CN/zh for all page requests. This is a natural-language/locale policy issue because the skill enforces a specific locale rather than offering the user a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown states 'Site: Default China site', which imposes a specific locale/site selection in natural language. While the skill is China-mainland ICP specific, this line presents a default locale choice rather than clearly framing it as a documented scope constraint or asking for user confirmation when cross-site ambiguity exists.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The boundary entry intentionally models out-of-scope topics, but its trigger terms are broad enough to match routine requests like DNS, real-name authentication, or server purchasing without a clear filing qualifier. Without explicit exclusion behavior in the catalog itself, these triggers can create ambiguity and cause the skill to activate merely to refuse, degrading routing accuracy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions, headings, and command descriptions only in Chinese, which can constitute a language/locale policy issue when users are not given an explicit choice or opt-in. The file does not state that the skill is region-specific or limited to Chinese-speaking users, so the locale constraint is not clearly justified here.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: aiohttp has 16 known advisory(ies) (CVE-2024-52303 (aiohttp has a memory leak when middleware is enabled when requesting a resource ); CVE-2026-54279 (aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence); CVE-2026-34514 (AIOHTTP has CRLF injection through multipart part content type header constructi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.