Back to skill

Security audit

huawei-cloud-install-openjiuwenswarm

Security checks for vulnerabilities and agentic risk

Overview

This installer is mostly aimed at deploying JiuwenSwarm, but it has several high-impact behaviors that are under-scoped or under-disclosed.

Install only in a disposable or dedicated Huawei Cloud development container. Review the external runtime source, avoid using a high-value API key, expect persistent files and global commands, and verify that no unrelated services are using the matched ports before running it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/04_start.py:14
Finding

Privileged Installer Can Terminate Unrelated Local Processes

Content
View full analysis

Vulnerability Details

File Location: scripts/04_start.py, lines 14–33
Vulnerability Type: Improper process ownership validation
Risk Level: Medium

Vulnerable code:

python
existing_ports = detect_ports_from_system()
if len(existing_ports) >= 4:
    print("[4/5] ⏭️ Already done: service already running, skip start", flush=True)
    sys.exit(0)

# If some ports are occupied (partial old instance), stop them first
if len(existing_ports) > 0:
    print(f"[4/5] 🛑 Stopping existing instance (ports found: {existing_ports})...", flush=True)
    try:
        # Kill processes occupying jiuwenswarm ports
        result = subprocess.run(
            "ss -tlnp 2>/dev/null | grep -E ':(517[0-9]|1809[0-9]|1900[0-9]|1901[0-9])' | grep -oP 'pid=\\K\\d+' | sort -u",
            shell=True, capture_output=True, text=True, timeout=5
        )
        pids = result.stdout.strip().split()
        for pid in pids:
            if pid:
                os.kill(int(pid), 9)
        # Wait for ports to be released
        time.sleep(2)
    except Exception:
        pass

Technical Analysis

Before starting JiuwenSwarm, the script treats any listener in broadly defined numeric port ranges as an existing JiuwenSwarm process. It extracts PIDs from system-wide ss -tlnp output and sends each matching process an unconditional SIGKILL.

The script does not verify:

  • The process owner or UID
  • The process executable or command line
  • Whether the process was created by this Skill
  • Whether the PID belongs to a previously recorded JiuwenSwarm process group
  • Whether the user approved terminating the process

Consequently, an unrelated service listening on a matching port can be mistaken for JiuwenSwarm. When this installer runs with root or equivalent privileges, it crosses a local user or service boundary by terminating a process that the port-binding user could not otherwise signal.

Thi ...[truncated 1212 chars]

Remediation
View remediation

Remediation Suggestions

  • Record the PID or process-group ID created by the Skill in a root-owned state file and terminate only that recorded instance.
  • Before signaling a process, verify its UID, executable path, command line, and expected deployment directory.
  • Replace broad port-pattern matching with checks against the exact configured JiuwenSwarm ports.
  • If an unexpected process owns a required port, abort startup and report the conflict rather than terminating it.
  • Require explicit user confirmation before stopping any process not provably created by the current deployment.
  • Prefer graceful shutdown with SIGTERM, a timeout, and controlled escalation instead of immediately sending SIGKILL.
  • Avoid suppressing all exceptions so ownership-validation and shutdown failures remain visible and auditable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (99)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation performs undeclared network access to fetch unrelated content for telemetry/statistics, that is behavior outside the stated deployment purpose. Hidden outbound requests are dangerous because they create unreviewed data flows and indicate the skill may do more than users consented to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation performs undeclared network access to fetch unrelated content for telemetry/statistics, that is behavior outside the stated deployment purpose. Hidden outbound requests are dangerous because they create unreviewed data flows and indicate the skill may do more than users consented to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the implementation performs undeclared network access to fetch unrelated content for telemetry/statistics, that is behavior outside the stated deployment purpose. Hidden outbound requests are dangerous because they create unreviewed data flows and indicate the skill may do more than users consented to.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

The skill is designed to read API credentials and place them into a .env file for service use. Even if permissions are set to 600, copying secrets from secure storage into a file expands their exposure surface and increases the chance of accidental leakage through logs, backups, process environments, or later file reads.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
### Security Features

- API credentials are read through a secure channel, no plaintext exposure
- .env file permissions set to 600, only readable/writable by the owner
- Does not store or transmit sensitive credential information

---

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
| 3 | `03_configure.py` | Configuring runtime |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
| 3 | `03_configure.py` | Configuring runtime |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 414)May include surrounding context.

md
| 3 | `03_configure.py` | Configuring runtime |

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill simultaneously claims the user must confirm before each write operation while other sections require silent execution of writes and installs. This contradiction is dangerous because it normalizes bypassing user consent for filesystem changes, package installation, service startup, and configuration writes.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires showing raw script stdout even though those scripts read local credentials and write them into configuration. Exposing unsanitized stdout is dangerous because secrets, paths, environment values, or other sensitive deployment data can be leaked directly to the user or logs.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Phase 3 explicitly configures .env, indicating the workflow writes credential-bearing configuration to disk as part of installation. In combination with silent execution and raw stdout requirements elsewhere in the skill, this makes secret exposure and unauthorized persistence materially more dangerous.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
|------|--------|----------------------------------------|
| 1 | `01_download.py` | Download mirror (300MB) via LFS API |
| 2 | `02_extract.py` | Extract archive to `/root/tools/jiuwenswarm/` |
| 3 | `03_configure.py` | Fix shebang, install global commands, init workspace, config .env |
| 4 | `04_start.py` | Start service, wait for ports |
| 5 | `05_url.py` | Output web URL |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The documented .env field mapping shows API_BASE and API_KEY are sourced from local settings and the kernel keyring, then placed into runtime configuration. This is a credential-handling risk because it transforms protected secrets into file-based application configuration that may be easier to access or exfiltrate.

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
| 4 | `04_start.py` | Start service, wait for ports |
| 5 | `05_url.py` | Output web URL |

### .env Field Mapping

| .env Field        | Source                                          | Value                                                |
| :---------------- | :---------------------------------------------- | :--------------------------------------------------- |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The explicit mention of API_KEY being base64-decoded from the HWCLOUD-Agent keyring into .env confirms secret extraction and persistence behavior. In this skill, that risk is amplified by mandatory automated execution, broad shell/network capabilities, and instructions to show script output to the user.

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
### .env Field Mapping

| .env Field        | Source                                          | Value                                                |
| :---------------- | :---------------------------------------------- | :--------------------------------------------------- |
| `API_BASE`        | `settings.json` -> `providers[*].base_url`       | Cloud service API endpoint                           |
| `API_KEY`         | kernel keyring `HWCLOUD-Agent` (base64 decoded)  | optional, read-only from keyring                     |

Scope Creep

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The declared IAM/read permissions materially understate the skill's real capabilities, which include installing software, modifying /usr/local/bin, writing configs, and killing/starting services. Under-declared privileges undermine security review and can let a high-impact operational skill appear less risky than it is.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 17)May include surrounding context.

md
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 35)May include surrounding context.

md
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 91)May include surrounding context.

md
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 93)May include surrounding context.

md
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 95)May include surrounding context.

md
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/04_start.py (reported line 79)May include surrounding context.

python
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 113)May include surrounding context.

python
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 114)May include surrounding context.

python
| Dependency check | Automatically check and install missing dependencies | Run phase scripts | All dependencies installed successfully |
| Image download | Successfully download 308MB image file | Check file existence | File size approximately 308MB |
| Image extraction | Successfully extract image to specified directory | Check directory structure | jiuwenswarm_runtime directory exists |
| Environment configuration | Correctly configure .env file | Check file content | Contains API_BASE, API_KEY, MODEL_NAME, MODEL_PROVIDER |
| Service startup | Successfully start all service processes | Check port status | All 4 ports are in LISTEN state |
| URL output | Correctly output Web access URL | Check output content | Correctly formatted URL |

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The policy example grants keyring:read over Resource: "*", which normalizes broad access to stored credentials and can enable credential harvesting beyond the minimum needed for this skill. In the context of an auto-deployment skill that downloads, configures, and starts services, access to API keys materially increases the consequences of compromise or malicious modification.

Content

Scanner excerpt · references/iam-policies.md (reported line 32)May include surrounding context.

md
"Effect": "Allow",
      "Action": [
        "hwcloud:settings:read",
        "keyring:read"
      ],
      "Resource": "*"
    }

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Referencing .env for verification becomes dangerous here because the surrounding instruction is to inspect it directly, and .env files frequently store credentials. This creates a credential exposure path during a normal operational check, even though the stated goal is only to learn port values.

Content

Scanner excerpt · references/verification-method.md (reported line 25)May include surrounding context.

Expected Result: JiuwenSwarm service processes should be listening on local ports (check .env for specific port values).

Step 3: Check .env File

bash
cat /root/.jiuwenswarm/config/.env

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The command cat /root/.jiuwenswarm/config/.env explicitly prints all configuration values, which may include secrets, to the console. This is a direct credential disclosure risk if shells are logged, monitored, shared, or copied into incident reports.

Content

Scanner excerpt · references/verification-method.md (reported line 28)May include surrounding context.

Step 3: Check .env File

bash
cat /root/.jiuwenswarm/config/.env

Expected Result: The file should exist and contain the correct configuration entries.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Sourcing the .env file causes every variable in it, including secrets, to be loaded into the shell environment. If the file is modified or untrusted, this broad import increases exposure and can also affect subsequent commands in unintended ways.

Content

Scanner excerpt · references/verification-method.md (reported line 58)May include surrounding context.

md
echo "=== JiuwenSwarm Deployment Verification ==="

# Source .env for dynamic port values
ENV_FILE="/root/.jiuwenswarm/config/.env"
if [ -f "$ENV_FILE" ]; then
    source "$ENV_FILE"

Static analysis

No suspicious patterns detected.