Back to skill

Security audit

huawei-cloud-modelarts-notebook-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Huawei Cloud notebook management, but its unsafe installer guidance and conflicting credential-handling fallback need review before installation.

Install only if you intend to let an agent manage Huawei Cloud ModelArts notebooks. Use a least-privilege IAM user, configure hcloud credentials outside the agent session, avoid the SDK fallback unless it is rewritten to use safe local credential mechanisms, and do not run the documented curl-to-bash installer without independently verifying the installer source and integrity.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims a narrow operational purpose, but its documented workflow expands into additional actions such as BSS pricing inquiries and references external files that may define broader behavior than declared. Description-behavior mismatch is dangerous because reviewers and users may authorize the skill under false assumptions, weakening informed consent and security oversight.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The SDK fallback embeds a pattern that requires AK/SK and project ID to be supplied directly in code, which directly contradicts earlier rules forbidding the agent from handling credentials in-session. This creates a clear path for secret solicitation, accidental logging, transcript exposure, or unsafe code generation that places long-lived cloud credentials into prompts, scripts, or process history.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The guide instructs users to fetch remote content over the network and immediately execute it with the shell, which prevents meaningful inspection and makes the installation path dependent on the integrity of the remote page and transport chain. If the upstream content, hosting account, CDN, or TLS trust path is compromised, users could execute arbitrary attacker-controlled commands on their systems.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 8)May include surrounding context.

Linux/macOS

bash
curl -sSL https://support.huaweicloud.com/qs-hcli/hcli_02_003.html | bash

Or download from: https://support.huaweicloud.com/qs-hcli/hcli_02_003.html

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The pipe into bash is the dangerous execution step that turns a remote content retrieval into immediate code execution. In a CLI installation guide for a cloud-management skill, this is especially risky because users are likely to run it on workstations or admin environments that also hold cloud credentials, increasing the blast radius of any compromise.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 8)May include surrounding context.

Linux/macOS

bash
curl -sSL https://support.huaweicloud.com/qs-hcli/hcli_02_003.html | bash

Or download from: https://support.huaweicloud.com/qs-hcli/hcli_02_003.html

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: huawei-cloud-modelarts-notebook-management
description: |
  Manage Huawei Cloud ModelArts Notebook instances through full lifecycle operations via hcloud CLI. Covers 31 API interfaces across 7 functional domains: instance management (create/list/show/update/delete/start/stop), lease management (show/renew), tag management (show/create/delete), image management (create/list/register/show/delete/sync/group operations), flavor and cluster queries (list flavors/switchable flavors/clusters/features), and dynamic storage management (list/attach/show/detach). All write operations require user confirmation before execution. Triggers include: "ModelArts notebook", "notebook实例", "创建notebook", "查询notebook", "启动notebook", "停止notebook", "删除notebook", "notebook镜像", "notebook规格", "notebook存储", "notebook标签", "notebook租期", "manage notebook", "notebook management", "ModelArts notebook management".
tags: [huawei-cloud, modelarts, notebook, ai, devtools]
---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document states that BSS pricing inquiries must use the cn-north-1 region and labels this as a fixed requirement, which can cause the skill to direct operations or billing-related requests to a hard-coded region without validating user intent, tenant configuration, or regulatory constraints. In a cloud-management skill, forcing a specific region for a pricing API can lead to misrouting, incorrect assumptions about account setup, and failures or unintended data handling across regions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file uses Chinese-only natural-language comments, usage text, and examples, and later emits Chinese-only status/output messages. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill switches into Chinese for core scope and exclusion instructions, and later includes additional Chinese-only operational guidance. This can impose a language/locale expectation on users who did not opt into Chinese, which matches the policy concern for forced language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.