Back to skill

Security audit

huawei-cloud-modelarts-resource-pool-management

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Huawei Cloud management skill, but it needs review because it combines high-impact cloud operations with unsafe install guidance and inconsistent credential-handling instructions.

Review this skill before installing. Use it only with a least-privilege Huawei Cloud IAM user, prefer read-only permissions unless you need writes, verify any hcloud installer out of band before running it, and do not let the agent see AK/SK values. Treat reset, delete, resize, plugin creation, and scheduled-event acceptance as high-impact actions requiring explicit confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (15)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This command fetches an external installer script and immediately executes it with bash, creating a direct arbitrary-code-execution path if the remote content is ever tampered with. In a skill used by an agent or end user, this is especially dangerous because it normalizes executing unaudited remote code as part of setup.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

Method 1: One-line Install (Recommended)

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Default install path: /usr/local/hcloud/, symlinked to /usr/local/bin/hcloud.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The non-interactive -y variant compounds the remote-script execution risk by reducing opportunities for the user to notice unexpected prompts or installation behavior. If the installer is malicious or altered, it can proceed unattended and make persistent system changes more easily.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 25)May include surrounding context.

To skip interactive prompts with defaults:

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Method 2: Step-by-step Install

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill invokes environment-sensitive capabilities and operational CLI flows but does not declare an explicit tool scope such as allowed-tools or permissions. That weakens containment and review because an agent may infer broader execution latitude than intended, especially in a skill that can perform infrastructure-changing operations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: huawei-cloud-modelarts-resource-pool-management
description: "Manage Huawei Cloud ModelArts dedicated resource pools (专属资源池) and node pools through full lifecycle operations via hcloud CLI. Covers 53 operations across 10 functional domains: resource pool management, pool nodes, node pool management, network resources, tag management, plugin management, jobs/tasks, scheduled events, OS configuration, and resource flavor/event queries. Includes BSS on-demand pricing inquiry before chargeable operations (create/expand) to inform users of costs. All write operations require user confirmation.\nTriggers include: \"资源池\", \"专属资源池\", \"resource pool\", \"创建资源池\", \"查询资源池\", \"删除资源池\", \"更新资源池\", \"资源池监控\", \"资源池节点\", \"pool node\", \"节点池\", \"node pool\", \"资源池网络\", \"pool network\", \"资源池标签\", \"pool tags\", \"插件\", \"plugin\", \"工作负载\", \"workload\", \"定时事件\", \"scheduled event\", \"OS配置\", \"规格列表\", \"ModelArts resource pool\", \"manage resource pool\", \"询价\", \"pricing\", \"按需价格\", \"价格查询\".\n"
---

# Huawei Cloud ModelArts Resource Pool Management

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description lists generic English triggers such as "plugin", "pricing", and "manage resource pool" alongside broad Chinese nouns like "插件". These are not tightly scoped invocation phrases and could match common conversation about software plugins or pricing rather than an explicit request to manage Huawei ModelArts resource pools.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The SDK fallback section instructs use of raw AK/SK values in agent-executed Python, directly contradicting the earlier security boundary that forbids handling credentials in-session. This creates a path for secret collection, in-memory exposure, logging leakage, and policy bypass whenever CLI fallback is triggered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The BatchResetPoolNodes example documents a destructive node reset operation but does not explicitly warn that it reinstalls the OS and can erase local data or configuration on the node. In an agent skill that guides operational actions, this omission increases the chance of accidental destructive use, especially because users may treat the command examples as safe runbooks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide recommends downloading and immediately executing a remote shell installer, which is a classic supply-chain risk. If the hosting location, transport, or script contents are compromised, users or agents would execute attacker-controlled code with local user privileges, potentially leading to credential theft or system compromise.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guide asserts that hcloud configure list is a safe presence-only check, but CLI config-list commands commonly display configured profile details that may include sensitive identifiers or partially masked credential metadata. In an agent setting, telling the agent to run this command can still expose secrets or account information into logs, transcripts, or tool output even if the author intended only a status check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide suggests setting --cli-lang=cn as the language example, which steers users toward a specific locale without offering alternatives or explaining why Chinese is required. This can violate language/locale policy when no opt-in or region-specific justification is provided.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-command-examples.md (reported line 914)May include surrounding context.

Rendering diagram...

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 58)May include surrounding context.

Rendering diagram...

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 38)May include surrounding context.

md
## Read vs Write Operations

- **Read operations** (list, show, query): Execute without confirmation
- **Write operations** (create, delete, update, patch, reboot, etc.): Require explicit user confirmation
- **Destructive operations** (delete pool, delete node pool, batch delete nodes): Show warning + require confirmation

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The note says hcloud CLI does not read environment variables and that hcloud configure set is the only supported credential configuration method. This is a tooling/workflow constraint rather than a language/locale issue, so it is not a strong policy violation, but the file does not present alternatives if organizational policy forbids local credential storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The optional mv $(pwd)/hcloud /usr/local/bin/ command changes a system PATH location, which can affect the host environment and may fail or require privilege escalation. The surrounding markdown does not disclose that this modifies system state or may need sudo depending on permissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.