Back to skill

Security audit

huawei-cloud-kunpeng-source-code-migrate

Security checks for vulnerabilities and agentic risk

Overview

The skill’s migration workflow is real and mostly disclosed, but it normalizes high-risk root-password SSH and plaintext credential persistence for cloud servers.

Install only if you are comfortable with an agent provisioning Huawei Cloud resources, uploading or scanning your source code on a remote host, and using root password SSH. Prefer an existing hardened server or a non-root key-based account, avoid writing MIGRATE_SSH_PASS to shell profiles, verify SSH host keys out of band, rotate/delete the generated root password after use, and review cleanup commands yourself before running them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ssh_client.py:245
Finding

SSH Connections Accept Unverified Host Keys

Content
View full analysis

Vulnerability Details

File Location: scripts/ssh_client.py, lines 245–249
Vulnerability Type: Missing SSH server identity verification
Risk Level: High

Vulnerable Code

python
client = paramiko.SSHClient()
client.set_missing_host_key_policy(paramiko.AutoAddPolicy())

try:
    client.connect(
        hostname=host,

Technical Analysis

The unified SSH client configures Paramiko with AutoAddPolicy, which automatically trusts any host key presented by a server when the host is not already known. The code does not load a trusted known-hosts file, pin an expected key or fingerprint, or require first-use fingerprint confirmation.

This affects every operation using _paramiko_connect, including remote command execution, file uploads, directory uploads, report downloads, and the initial connection test. Password authentication does not authenticate the server to the client; it only authenticates the client to whichever endpoint completed the SSH handshake.

The password is removed from os.environ after connection, but that does not mitigate disclosure to an impersonating SSH endpoint because the password has already been submitted during authentication.

Attack Path

  1. The user configures an authorized remote server through KUNPENG_SERVER_HOST, or the provisioning process stores the new server address.
  2. A network-positioned attacker intercepts or redirects the connection through DNS spoofing, routing manipulation, a compromised gateway, or another applicable network attack.
  3. The attacker presents an arbitrary SSH host key.
  4. AutoAddPolicy accepts that key without warning or verification.
  5. The client submits MIGRATE_SSH_PASS to the impersonating endpoint.
  6. The attacker captures the root or privileged SSH password.
  7. The attacker can subsequently authenticate to the legitimate server if it is reachable. The attacker may also return forged command output, receive uploaded source or installation files, or provide m ...[truncated 747 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace AutoAddPolicy with strict host-key rejection:
python
client = paramiko.SSHClient()
client.load_system_host_keys()
client.load_host_keys(user_known_hosts_path)
client.set_missing_host_key_policy(paramiko.RejectPolicy())
  1. For newly provisioned servers, obtain the expected host-key fingerprint through a trusted cloud control-plane channel or console and compare it before password authentication.
  2. If trust-on-first-use is necessary, display the SHA-256 fingerprint and require explicit out-of-band user verification before persisting it.
  3. Store accepted keys in a user-owned known-hosts file with restrictive permissions.
  4. Reject changed keys and provide an explicit warning rather than silently replacing or accepting them.
  5. Apply the same verification procedure to direct Paramiko examples in the Skill documentation so agents do not bypass the hardened helper.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/provision_kunpeng_server.sh:576
Finding

Root SSH Password Is Written to Predictable Shared Temporary Files Before Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: scripts/provision_kunpeng_server.sh, lines 576–643
Vulnerability Type: Insecure temporary-file handling and transient plaintext credential exposure
Risk Level: Medium

Vulnerable Code

bash
# Save the password to a secure temp variable for save_connection_info.
# The password is written to the env file (chmod 600) later.
echo "${server_password}" > "${TMP_DIR:-/tmp}/.migrate_ecs_pass"
chmod 600 "${TMP_DIR:-/tmp}/.migrate_ecs_pass" 2>/dev/null || true
server_password=""

The password is later moved into another predictable file:

bash
save_connection_info() {
    local env_file="/tmp/kunpeng_server_env.sh"
    local pass_file="${TMP_DIR:-/tmp}/.migrate_ecs_pass"

    local saved_password=""
    if [ -f "${pass_file}" ]; then
        saved_password=$(cat "${pass_file}")
        shred -u "${pass_file}" 2>/dev/null || rm -f "${pass_file}"
    else
        log_warn "Password temp file not found: ${pass_file}"
        log_warn "MIGRATE_SSH_PASS will NOT be written to env file."
        log_warn "You will need to reset the password manually via:"
        log_warn "  hcloud ECS ResetServerPassword --cli-region=${REGION} --server_id=${SERVER_ID} --reset-password.new_password=<new_pass>"
    fi

    {
        echo "# Kunpeng ECS connection info (SSH via paramiko + secret env var)"
        echo "export KUNPENG_SERVER_HOST=\"${EIP_ADDRESS}\""
        echo "export KUNPENG_SERVER_PORT=\"22\""
        echo "export KUNPENG_SERVER_USER=\"root\""
        echo "export KUNPENG_SERVER_ID=\"${SERVER_ID}\""
        echo "export KUNPENG_SERVER_REGION=\"${REGION}\""
        if [ -n "${saved_password}" ]; then
            echo "export MIGRATE_SSH_PASS=\"${saved_password}\""
        fi
    } > "${env_file}"
    chmod 600 "${env_file}"

Technical Analysis

The provisioning script stores the generated ECS root password in two fixed paths under shared temporary storage:

  • ${TMP_DIR:-/tmp}/.migrate_ecs_pass
  • `/tmp ...[truncated 2549 chars]
Remediation
View remediation

Remediation Suggestions

  1. Set a restrictive umask before creating any credential-bearing file:
bash
umask 077
  1. Create the intermediate password file with a unique, securely created path:
bash
pass_file=$(mktemp "${TMPDIR:-/tmp}/migrate_ecs_pass.XXXXXX")
chmod 600 "$pass_file"
printf '%s\n' "$server_password" > "$pass_file"
  1. Use an exit trap to remove sensitive temporary files on success, failure, interruption, or timeout:
bash
trap 'rm -f -- "${pass_file:-}" "${env_tmp:-}"' EXIT HUP INT TERM
  1. Create the environment file as a mode-0600 temporary file in the destination directory, verify that it is a regular file owned by the current user, write its contents, and atomically rename it to the final path.
  2. Do not ignore failures to apply restrictive permissions. Abort provisioning output handling if secure file creation cannot be guaranteed.
  3. Avoid fixed shared /tmp names where possible. Prefer a private runtime directory owned by the current user.
  4. Delete the environment file as soon as report retrieval and other SSH operations are complete, and recommend rotating or disabling the temporary root password.
  5. Where supported, avoid persistent root password authentication entirely; provision a narrowly scoped administrative account or a verified ephemeral access mechanism.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (138)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code aligns with one supporting subtask mentioned in the description: installing DevKit CLI. However, the declared purpose presents the skill as a complete migration assessment workflow, including remote server access, analysis execution, report generation, and optional cloud provisioning. This code chunk does none of those core functions; it only installs and verifies the DevKit tool locally/remotely if invoked elsewhere. Because the actual behavior is a narrower installer utility rather than the described end-to-end assessment/provisioning skill, the description materially overstates the implemented capabilities.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

6. hcloud CLI install & configure (Step 3d only):

bash
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -xzf huaweicloud-cli-linux-amd64.tar.gz && chmod +x hcloud && sudo mv hcloud /usr/local/bin/
hcloud configure set --cli-region=cn-southwest-2 --cli-access-key=<your-ak> --cli-secret-key=<your-sk>
hcloud version   # Expected: >= 3.2.0

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 463)May include surrounding context.

md
| [acceptance-criteria.md](references/acceptance-criteria.md) | Acceptance criteria |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 86)May include surrounding context.

md
| Action | hcloud CLI Command | API | Description |
|--------|--------------------|-----|-------------|
| `ecs:servers:delete` | `hcloud ECS DeleteServers` | POST /v1/{project_id}/cloudservers/delete | Delete the ECS instance |
| `eip:publicips:delete` | `hcloud EIP DeletePublicip` | DELETE /v1/{project_id}/publicips/{publicip_id} | Release the EIP |
| `vpc:subnets:delete` | `hcloud VPC DeleteSubnet` | DELETE /v1/{project_id}/vpcs/{vpc_id}/subnets/{subnet_id} | Delete the subnet |
| `vpc:securityGroups:delete` | `hcloud VPC DeleteSecurityGroup` | DELETE /v1/{project_id}/security-groups/{security_group_id} | Delete the security group |
| `vpc:vpcs:delete` | `hcloud VPC DeleteVpc` | DELETE /v1/{project_id}/vpcs/{vpc_id} | Delete the VPC |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 87)May include surrounding context.

md
|--------|--------------------|-----|-------------|
| `ecs:servers:delete` | `hcloud ECS DeleteServers` | POST /v1/{project_id}/cloudservers/delete | Delete the ECS instance |
| `eip:publicips:delete` | `hcloud EIP DeletePublicip` | DELETE /v1/{project_id}/publicips/{publicip_id} | Release the EIP |
| `vpc:subnets:delete` | `hcloud VPC DeleteSubnet` | DELETE /v1/{project_id}/vpcs/{vpc_id}/subnets/{subnet_id} | Delete the subnet |
| `vpc:securityGroups:delete` | `hcloud VPC DeleteSecurityGroup` | DELETE /v1/{project_id}/security-groups/{security_group_id} | Delete the security group |
| `vpc:vpcs:delete` | `hcloud VPC DeleteVpc` | DELETE /v1/{project_id}/vpcs/{vpc_id} | Delete the VPC |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 88)May include surrounding context.

md
| `ecs:servers:delete` | `hcloud ECS DeleteServers` | POST /v1/{project_id}/cloudservers/delete | Delete the ECS instance |
| `eip:publicips:delete` | `hcloud EIP DeletePublicip` | DELETE /v1/{project_id}/publicips/{publicip_id} | Release the EIP |
| `vpc:subnets:delete` | `hcloud VPC DeleteSubnet` | DELETE /v1/{project_id}/vpcs/{vpc_id}/subnets/{subnet_id} | Delete the subnet |
| `vpc:securityGroups:delete` | `hcloud VPC DeleteSecurityGroup` | DELETE /v1/{project_id}/security-groups/{security_group_id} | Delete the security group |
| `vpc:vpcs:delete` | `hcloud VPC DeleteVpc` | DELETE /v1/{project_id}/vpcs/{vpc_id} | Delete the VPC |

> **⚠️ Cleanup is always manual.** The AI presents the delete commands as text but never executes them. The user must run them in their own terminal. See [prerequisites.md → Resource Cleanup Reminder](prerequisites.md#resource-cleanup-reminder).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 89)May include surrounding context.

md
| `eip:publicips:delete` | `hcloud EIP DeletePublicip` | DELETE /v1/{project_id}/publicips/{publicip_id} | Release the EIP |
| `vpc:subnets:delete` | `hcloud VPC DeleteSubnet` | DELETE /v1/{project_id}/vpcs/{vpc_id}/subnets/{subnet_id} | Delete the subnet |
| `vpc:securityGroups:delete` | `hcloud VPC DeleteSecurityGroup` | DELETE /v1/{project_id}/security-groups/{security_group_id} | Delete the security group |
| `vpc:vpcs:delete` | `hcloud VPC DeleteVpc` | DELETE /v1/{project_id}/vpcs/{vpc_id} | Delete the VPC |

> **⚠️ Cleanup is always manual.** The AI presents the delete commands as text but never executes them. The user must run them in their own terminal. See [prerequisites.md → Resource Cleanup Reminder](prerequisites.md#resource-cleanup-reminder).

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document explicitly claims the SSH password is 'never written to disk,' but later instructs users and the provisioning workflow to store MIGRATE_SSH_PASS in /tmp/kunpeng_server_env.sh and even in shell startup files. That contradiction is security-relevant because operators may trust the stronger claim and underestimate credential exposure from filesystem persistence.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
97% confidence
Finding

Although this is not a malware backdoor in the classic sense, the matched content does create persistence for sensitive credentials by writing them into shell initialization files. Persisting a root SSH password and host details in ~/.bashrc is dangerous because it survives reboots, may be copied into backups or dotfile sync tools, and can be harvested by any process or user with access to that account.

Content

Scanner excerpt · references/prerequisites.md (reported line 113)May include surrounding context.

/tmpdirectory is typically cleared on system reboot. If you need persistence across reboots, use~/.bashrcinstead (see below). The/tmp/kunpeng_server_env.sh` file is primarily designed for the "new server" provisioning workflow and for persisting credentials during a single work session.

Persistent across reboots (via shell profile):

bash
# Add to ~/.bashrc (Bash) or ~/.zshrc (Zsh)
echo "export MIGRATE_SSH_PASS='<your-password>'" >> ~/.bashrc
echo "export KUNPENG_SERVER_HOST='<your-server-ip>'" >> ~/.bashrc
echo "export KUNPENG_SERVER_PORT='22'" >> ~/.bashrc
echo "export KUNPENG_SERVER_USER='root'" >> ~/.bashrc
source ~/.bashrc

Credential Resolution Priority

ssh_client.py resolves credentials in the following order (first match wins):

PrioritySourceUse Case
1Current process env vars (export in current shell)Existing server workflow — user sets vars manually in the active session
2`/tmp/kunpeng_se

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/troubleshooting.md (reported line 229)May include surrounding context.

built-in ssh_client.py test subcommand to verify the paramiko password connection:

text
→ Run: python <skill_dir>/scripts/ssh_client.py test
→ The script reads MIGRATE_SSH_PASS from env var and verifies the connection.

4. Environment variables not persisted

Problem: Environment variables are lost after terminal restart.

Solution: Add to shell profile (Linux/macOS):

bash
echo 'export KUNPENG_SERVER_HOST=<your-server-ip>' >> ~/.bashrc
source ~/.bashrc

Or set as Windows User environment variable (persistent across restarts).


SSH Connection Issues

1. Authentication failed

Problem: SSH connection fails with Authentication failed.

Root cause: The MIGRATE_SSH_PASS environment variable is not set, is incorrect, or the username is wrong.

Solution: Verify the MIGRATE_SSH_PASS environment variable is set to the correct password and KUNPENG_SERVER_USER is correct. Then re-run the built-in ssh_client.py test subcommand to verify

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The script is intentionally designed to enable direct root password login over SSH by setting the root password and reconfiguring sshd to allow PasswordAuthentication yes and PermitRootLogin yes. In the context of an Internet-reachable cloud VM with an attached public IP, this significantly increases the likelihood and impact of brute-force attacks, credential theft, and full-host compromise.

Content

Scanner excerpt · scripts/provision_kunpeng_server.sh (reported line 47)May include surrounding context.

sh
#        PermitRootLogin prohibit-password   (blocks root password login)
#        PasswordAuthentication no           (blocks password auth entirely)
#      Setting adminPass alone (even without user_data) writes the password
#      to /etc/shadow but SSH still rejects password-based root login.
#      Fix: inject a cloud-init user_data shell script that:
#        a) sets root password via chpasswd
#        b) sets PermitRootLogin yes and PasswordAuthentication yes in sshd_config

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The comments materially misdescribe the script’s behavior: it does generate a root password, enables PermitRootLogin yes and PasswordAuthentication yes, and persists the password for later use. This kind of deceptive or stale documentation is dangerous because operators may approve execution under a false belief that only passwordless SSH is used, masking a substantial expansion of attack surface.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This section documents and implements a workflow that changes the guest to accept password-based root SSH access specifically because the default hardened configuration blocks it. That is a real weakening of host security, and in this skill context it is more dangerous because the script also provisions a public IP and an SSH ingress rule, making remote compromise paths immediately reachable.

Content

Scanner excerpt · scripts/provision_kunpeng_server.sh (reported line 474)May include surrounding context.

sh
#   This is necessary because EulerOS 2.0's default sshd_config has:
    #     PermitRootLogin prohibit-password   (blocks root password login)
    #     PasswordAuthentication no           (blocks password auth entirely)
    #   Even if adminPass correctly sets /etc/shadow, SSH still rejects
    #   password-based root login. The user_data script fixes sshd_config.
    #
    #   The password is passed to the Python script via stdin (not argv) so

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs sensitive actions involving shell execution, environment-variable credential handling, file transfer, and cloud provisioning, yet it declares no explicit tool scope or permission boundaries. Without a machine-readable allowlist, an agent framework may expose broader capabilities than intended, increasing the chance of unauthorized command execution or misuse of credentials and files.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill instructs use of sudo to install the hcloud binary fetched from a remote URL into /usr/local/bin, which grants elevated privileges to a downloaded artifact. If the download source is compromised, tampered with, or not integrity-verified, this can lead to privileged code execution on the local system.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

6. hcloud CLI install & configure (Step 3d only):

bash
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -xzf huaweicloud-cli-linux-amd64.tar.gz && chmod +x hcloud && sudo mv hcloud /usr/local/bin/
hcloud configure set --cli-region=cn-southwest-2 --cli-access-key=<your-ak> --cli-secret-key=<your-sk>
hcloud version   # Expected: >= 3.2.0

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
81% confidence
Finding

The skill provisions a server with a generated root password and stores it in /tmp/kunpeng_server_env.sh, then sources that file for later use. Even with chmod 600, placing credentials in /tmp and normalizing root-password workflows increases the risk of credential disclosure, reuse, accidental persistence, or compromise of a newly provisioned privileged account.

Content

Scanner excerpt · SKILL.md (reported line 337)May include surrounding context.

md
2. Confirm provisioning with user (present spec and estimated cost)
3. Execute: `bash <skill_dir>/scripts/provision_kunpeng_server.sh --confirm`
   - Creates VPC → Subnet → Security Group + SSH rule → EIP → ECS
   - Generates random root password, saves to `/tmp/kunpeng_server_env.sh` as `MIGRATE_SSH_PASS` (chmod 600)
4. Load env: `source /tmp/kunpeng_server_env.sh`
5. Verify SSH: `python <skill_dir>/scripts/ssh_client.py test`
6. Proceed to Task 1

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 95)May include surrounding context.

md
| # | Pattern | Description |
|---|---------|-------------|
| 1 | Install DevKit without checking existing installation | Risk of clobbering prior config — must verify first |
| 2 | Miss `.devkit` hidden file during copy | Will cause execvp failure |
| 3 | Use wrong architecture package | `cannot execute binary file` error |
| 4 | Scan without verifying source path | May scan non-existent directory |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 227)May include surrounding context.

md
| # | Pattern | Description |
|---|---------|-------------|
| 1 | Install DevKit without checking existing installation | Risk of clobbering prior config — must verify first |
| 2 | Miss `.devkit` hidden file during copy | Will cause execvp failure |
| 3 | Use wrong architecture package | `cannot execute binary file` error |
| 4 | Scan without verifying source path | May scan non-existent directory |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
| 2 | Miss `.devkit` hidden file during copy | Will cause execvp failure |
| 3 | Use wrong architecture package | `cannot execute binary file` error |
| 4 | Scan without verifying source path | May scan non-existent directory |
| 5 | Assume source code path without asking | Must ask the user |

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 99)May include surrounding context.

md
| 2 | Miss `.devkit` hidden file during copy | Will cause execvp failure |
| 3 | Use wrong architecture package | `cannot execute binary file` error |
| 4 | Scan without verifying source path | May scan non-existent directory |
| 5 | Assume source code path without asking | Must ask the user |

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 256)May include surrounding context.

md
| 2 | Miss `.devkit` hidden file during copy | Will cause execvp failure |
| 3 | Use wrong architecture package | `cannot execute binary file` error |
| 4 | Scan without verifying source path | May scan non-existent directory |
| 5 | Assume source code path without asking | Must ask the user |

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 122)May include surrounding context.

md
|---|---------|-------------|
| 1 | Skip server availability check | Must ask user first |
| 2 | Assume user has a server | User may not have one |
| 3 | Provision ECS without confirmation | Creates paid resources without consent |
| 4 | Hardcode server IP | Must come from environment variables or provisioning |
| 5 | Skip environment variable verification | Must verify before attempting SSH |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 122)May include surrounding context.

md
|---|---------|-------------|
| 1 | Skip server availability check | Must ask user first |
| 2 | Assume user has a server | User may not have one |
| 3 | Provision ECS without confirmation | Creates paid resources without consent |
| 4 | Hardcode server IP | Must come from environment variables or provisioning |
| 5 | Skip environment variable verification | Must verify before attempting SSH |

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 177)May include surrounding context.

md
|---|---------|-------------|
| 1 | Use x86 flavor for Kunpeng assessment | Defeats the purpose of ARM64 migration |
| 2 | Open SSH to 0.0.0.0/0 without agent IP restriction | Security risk |
| 3 | Save password in world-readable file | Must use chmod 600 |
| 4 | Skip SSH verification after provisioning | May proceed with unreachable server |
| 5 | Not remind user about ongoing costs | User may forget to delete server |
| 6 | **AI auto-executes `hcloud ... Delete*` commands** | **HIGH-RISK: AI must NEVER auto-delete resources** |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 35)May include surrounding context.

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz" tar -xzf huaweicloud-cli-linux-amd64.tar.gz chmod +x hcloud sudo mv hcloud /usr/local/bin/

text

### Linux (ARM64)

Static analysis

No suspicious patterns detected.