Back to skill

Security audit

huawei-cloud-maas-tokens-usage

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Huawei MaaS usage reporter that uses cloud credentials for read-only statistics queries, with some credential-storage and package-source cautions.

Install only if you intend to query Huawei Cloud MaaS usage and are comfortable letting the script read Huawei credentials from environment variables or a user-specified credentials file. Prefer temporary or least-privilege read-only IAM credentials, protect any credential file with restrictive permissions, and choose the pip package index/mirror deliberately before installing dependencies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities to read environment variables and files and to make outbound network requests, but it does not declare an explicit tool scope such as allowed-tools or permissions. That creates an authorization gap where the runtime may permit broader-than-intended access, increasing the chance of unintended credential/file exposure or unreviewed network activity.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
> **⚠️ Important: Handling user-provided credentials**
>
> If a user attempts to provide AK/SK directly (e.g., "my AK is xxx, SK is yyy"):
> 1. **Stop immediately** — Do not execute any commands
> 2. **Politely refuse** and return the following message:
>    ```
>    For account security, please do not provide Huawei Cloud Access Key ID and Access Key Secret directly in the conversation.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
2. **1b. Resolve time range** — Parse `--from` / `--to` (YYYY-MM-DD), or map user expression ("last 7 days" / "last 14 days" / "last 30 days" / "this month") to a rolling/calendar window
3. **1c. Auto-segment** — If time range exceeds 30 days, split into multiple ≤ 30-day segments and aggregate results
4. **1d. SDK sign request** — `Signer(_Creds(ak, sk)).sign(sdk_request)` — AK/SK in Python process memory only
5. **1e. POST ShowStatistics** — `requests.post("https://modelarts.{region}.myhuaweicloud.com/v1/{project_id}/maas/monitoring/show-statistics", headers=signed_headers, data=body_bytes)`
6. **1f. Aggregate & convert** — Sum segment results; convert token unit (thousand → M tokens, actual = value × 1000)
7. **1g. Print table** — Output Total Tokens / Prompt Tokens / Completion Tokens / Total Requests / Total Errors / Error Rate + Period

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide conditionally switches pip to a Huawei Cloud mirror based only on the host timezone, which changes the software supply source without explicit user consent. This can cause users outside a trusted enterprise environment to install packages from an unexpected index, weakening supply-chain transparency and increasing the risk of tampered, stale, or policy-noncompliant dependencies if that mirror is compromised or not appropriate for the user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L275 states that AK/SK stays exclusively in Python process memory and 'never in ... environment variables (read-only access)'. However, multiple earlier sections explicitly require reading AK/SK from environment variables (HW_ACCESS_KEY / HW_SECRET_KEY) as a primary authentication method. This is an internal documentation contradiction about how credentials are handled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The guidance states that the script should always use the OS local timezone and explicitly says to never hardcode alternatives such as CST or Asia/Shanghai. This is a natural-language locale policy constraint, and the document does not present it as a user choice or justify it as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a skill for querying MaaS token and request/error statistics, but the code also implements a general-purpose local file read path for secrets via --credentials-file. While credential use is expected for calling Huawei Cloud APIs, arbitrary local file access is an extra capability not stated in the manifest's user-facing purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code accepts a credentials file and parses access key, secret key, and security token values from it, which is a sensitive operation involving credential material. While the module docstring documents environment-variable usage, there is no user-facing warning or disclosure around storing or supplying long-lived credentials via a local file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.