Back to skill

Security audit

huawei-cloud-kubectl-cce-installer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Huawei Cloud CCE read-only queries and local kubectl-cce installation, but it automatically retries authenticated commands with TLS verification disabled and installs remote-built binaries, which deserves Review before use.

Review before installing. Prefer a user-writable bin directory, avoid sudo unless you intentionally want a system-wide install, and do not proceed with the insecure TLS retry for credentialed commands unless you have independently verified the endpoint and understand the interception risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/plugin-usage.md:56
Finding

Automatic retry disables upstream TLS certificate verification

Content
View full analysis

Vulnerability Details

File Location: references/plugin-usage.md:56-58; also instructed by SKILL.md:87-88
Vulnerability Type: Improper certificate validation / insecure TLS fallback
Risk Level: High

Vulnerable Snippets

From references/plugin-usage.md:56-58:

markdown
## x509 TLS Retry

If a `kubectl cce` command returns an `x509` certificate-validation error, repeat the same command with `--cce-insecure-upstream-tls=true` immediately after `cce`. For example: `kubectl cce --cce-insecure-upstream-tls=true --cluster-id <cluster-id> ...`. Use this option only when that TLS validation error occurs.

From SKILL.md:87-88:

markdown
If a command fails with an x509 upstream TLS validation error, retry that same command once
with `--cce-insecure-upstream-tls=true` immediately after `cce`.

Technical Analysis

The Skill directs the Agent to automatically repeat a failed CCE resource query with upstream TLS certificate validation disabled. A certificate-validation failure is a security boundary: it indicates that the client cannot authenticate the remote endpoint. Turning verification off in response converts that failure into an unauthenticated connection.

The retry does not require separate user approval, certificate fingerprint verification, a user-approved private certificate authority, or any equivalent endpoint-authentication mechanism. The same authenticated query is repeated, potentially including plugin credentials supplied through environment variables or CLI options.

This is reachable during the Skill's documented resource-query workflow whenever the upstream connection reports an x509 validation error. Although the insecure mode is conditional and limited to one retry, that condition does not prevent exploitation because a network-path attacker can induce the certificate error by presenting an untrusted certificate.

Attack Path

  1. The user authorizes a read-only kubectl cce query against a specified ...[truncated 1312 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic --cce-insecure-upstream-tls=true retry from both SKILL.md and references/plugin-usage.md.
  2. Treat every x509 validation error as a hard failure and stop the query.
  3. Direct the user to repair the certificate trust chain, verify system time, confirm the configured endpoint, or install the appropriate trusted CA certificate.
  4. If insecure TLS must remain available for exceptional diagnostics, require explicit per-command user approval after displaying the affected endpoint and interception risk.
  5. Do not transmit credentials during an insecure diagnostic connection. Use a non-authenticated connectivity check where possible.
  6. For private certificate deployments, support an explicit CA bundle or pinned certificate/public-key fingerprint instead of disabling verification.
  7. Add acceptance tests confirming that certificate failures cannot silently or automatically transition to an insecure authenticated connection.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- Source-build fallback additionally requires `git` and Go.
- The selected `--bin-dir` must be writable. `/usr/local/bin` commonly requires elevated local permission.
- Network operations use these defaults: 10-second connection timeout, 300-second download timeout, 600-second source-clone timeout, and 900-second build timeout.
- Installation does not need Huawei Cloud credentials. Never print or store credentials, tokens, or kubeconfig content.

## Installer Commands

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 27)May include surrounding context.

md
- Source-build fallback additionally requires `git` and Go.
- The selected `--bin-dir` must be writable. `/usr/local/bin` commonly requires elevated local permission.
- Network operations use these defaults: 10-second connection timeout, 300-second download timeout, 600-second source-clone timeout, and 900-second build timeout.
- Installation does not need Huawei Cloud credentials. Never print or store credentials, tokens, or kubeconfig content.

## Installer Commands

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/installation.md (reported line 11)May include surrounding context.

md
- Source-build fallback additionally requires `git` and Go.
- The selected `--bin-dir` must be writable. `/usr/local/bin` commonly requires elevated local permission.
- Network operations use these defaults: 10-second connection timeout, 300-second download timeout, 600-second source-clone timeout, and 900-second build timeout.
- Installation does not need Huawei Cloud credentials. Never print or store credentials, tokens, or kubeconfig content.

## Installer Commands

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/plugin-usage.md (reported line 17)May include surrounding context.

md
- Source-build fallback additionally requires `git` and Go.
- The selected `--bin-dir` must be writable. `/usr/local/bin` commonly requires elevated local permission.
- Network operations use these defaults: 10-second connection timeout, 300-second download timeout, 600-second source-clone timeout, and 900-second build timeout.
- Installation does not need Huawei Cloud credentials. Never print or store credentials, tokens, or kubeconfig content.

## Installer Commands

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell commands, including installer and kubectl operations, but does not declare an explicit tool scope such as allowed-tools or permissions. This increases the risk of unintended or overly broad shell execution because the runtime boundaries are not documented or constrained at the skill level.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

The skill includes a sudo-based execution path for installing or replacing binaries, which can modify privileged system locations and magnify the consequences of any script misuse or tampering. Even with confirmation requirements, encouraging root execution in a skill materially increases host risk if the referenced installer is unsafe, altered, or invoked with attacker-influenced parameters.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

bash
   bash scripts/install_kubectl_cce.sh --bin-dir <directory>
   sudo bash scripts/install_kubectl_cce.sh --execute --bin-dir <directory>
  1. Verify installation with kubectl version --client and kubectl plugin list, then run only the requested read-only resource query.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says kubectl and kubectl-cce should be installed only when they are missing locally, but the script supports a reinstall path via --reinstall and later replaces an existing kubectl-cce binary. This is a semantic mismatch because the code permits modifying an already-present installation rather than limiting itself to missing-prerequisite repair/install behavior.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_kubectl_cce.sh (reported line 113)May include surrounding context.

sh
local source="$1"
  local destination="$2"
  cp "$source" "$destination"
  chmod 0755 "$destination"
}

install_latest_kubectl_from_obs() {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The installer falls back to cloning and building kubectl and kubectl-cce directly from remote source repositories, then installs the resulting binaries into a system binary directory. This expands trust from fixed release artifacts to mutable source/build toolchains and enables supply-chain compromise if the repository, tag, or build environment is malicious or tampered with.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.