Back to skill

Security audit

huawei-cloud-modelarts-training-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and read-only for ModelArts diagnosis, but it asks users to weaken TLS security and run unverified installer scripts while using cloud credentials and logs.

Install only if you are comfortable giving the agent read-only access to ModelArts training job metadata and logs. Keep TLS verification enabled, avoid the non-interactive curl-to-bash installer unless you can verify the source, and review any uninstall commands before running them because they can remove local hcloud configuration.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

TLS Certificate Verification Disabled for Authenticated Cloud API Traffic

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60–65
Vulnerability Type: Improper certificate validation
Risk Level: Medium

Code snippet:

markdown
### Authentication Configuration

- AK/SK configured in `~/.hcloud/config.json`
- Default region: `cn-north-4`
- `project_id` configured in profile
- `skipSecureVerify=true` (for WSL environment)

Technical Analysis

The Skill instructs WSL users to configure skipSecureVerify=true alongside their authenticated hcloud profile. This disables validation of the server certificate used for cloud API connections.

Consequently, possession of a certificate trusted by the client is no longer required to impersonate the remote endpoint. A network-positioned attacker could intercept authenticated ModelArts requests, observe returned job information and logs, or provide forged API responses. The Skill then treats fields from those responses—such as tracebacks, events, and failure-analysis results—as trusted diagnostic evidence.

The documented setting is not constrained to a one-time connectivity test, and no compensating control such as certificate pinning or a private CA configuration is specified.

Attack Path

  1. A WSL user follows the prerequisite and enables skipSecureVerify=true in the hcloud configuration.
  2. The user invokes the Skill to diagnose a ModelArts training job.
  3. The Skill executes authenticated hcloud requests for job details, events, stages, or logs.
  4. An attacker with a network interception position presents an untrusted certificate and impersonates the cloud endpoint.
  5. Because certificate verification is disabled, the CLI accepts the connection.
  6. The attacker can observe API traffic and return manipulated job metadata, diagnostic events, log content, or temporary log-link responses.
  7. The Skill may disclose sensitive diagnostic data to the interceptor or generate false conclusions and remediation advice fro ...[truncated 539 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to set skipSecureVerify=true.
  • Keep TLS certificate verification enabled for all authenticated cloud API operations.
  • Resolve WSL certificate errors by installing the appropriate CA chain and configuring hcloud to use the correct trusted CA store.
  • If disabling verification is retained solely for troubleshooting, make it an explicit, temporary, user-confirmed diagnostic step that does not send credentials or access sensitive resources.
  • Document how to restore secure verification immediately after troubleshooting.
  • Add a preflight check that refuses authenticated diagnosis when secure certificate verification is disabled.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (42)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

This command downloads an external shell script and immediately executes it, creating a classic supply-chain execution path. If the hosting bucket, DNS, transport path, or script contents are compromised, users could run arbitrary code on their machines with little opportunity for review.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The non-interactive variant is especially risky because it both executes a remote script and suppresses user confirmation. This increases the chance of silent compromise in automated or copy-paste installations, making the installation guide more dangerous in practice.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The Dockerfile example pulls and runs a remote installer script during image build, embedding an unverified network dependency directly into the supply chain. A compromise of the script source could poison every downstream image built from these instructions.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 105)May include surrounding context.

Custom Image

dockerfile
FROM ubuntu:latest
RUN apt-get update -y && apt-get install curl -y
RUN curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y
WORKDIR /workspace
ENTRYPOINT ["/usr/local/bin/hcloud"]

External Script Fetching

High
Category
Supply Chain
Confidence
91% confidence
Finding

Even though this variant installs to ~/.local/bin, it still downloads and executes an unverified remote script. The absence of privilege does not remove the risk of arbitrary code execution under the user's account.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 160)May include surrounding context.

sudo bash ./hcloud_install.sh

Or install to user directory

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -d ~/.local/bin

text

#### Command Not Found

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The update/reinstall section repeats the remote-script execution pattern, meaning users may reintroduce supply-chain risk during maintenance as well as initial installation. Recommending this in an update path normalizes unsafe operational behavior.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 205)May include surrounding context.

hcloud update

Or reinstall latest version

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Uninstall KooCLI

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

This uninstall command permanently deletes a system binary with sudo rm -f /usr/local/bin/hcloud. In context it is legitimate maintenance guidance, but it is still a destructive privileged command that could cause accidental removal or be dangerous if copied blindly into the wrong environment.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 211)May include surrounding context.

Uninstall KooCLI

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively deletes the installation directory under /usr/local with elevated privileges. Although intended for uninstall, recursive privileged deletion is inherently risky if paths are mistyped or copied into a different environment, and the guide lacks a prominent safety warning.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively deletes the installation directory under /usr/local with elevated privileges. Although intended for uninstall, recursive privileged deletion is inherently risky if paths are mistyped or copied into a different environment, and the guide lacks a prominent safety warning.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 212)May include surrounding context.

bash
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deleting ~/.hcloud/ removes local CLI configuration and potentially saved credentials or profiles. In a cloud CLI context this is more sensitive than ordinary cache cleanup because it may erase account settings and operational context without warning.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deleting ~/.hcloud/ removes local CLI configuration and potentially saved credentials or profiles. In a cloud CLI context this is more sensitive than ordinary cache cleanup because it may erase account settings and operational context without warning.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 213)May include surrounding context.

md
# Linux/macOS manual uninstallation:
sudo rm -f /usr/local/bin/hcloud
sudo rm -rf /usr/local/hcloud/
rm -rf ~/.hcloud/

# Windows manual uninstallation:
# 1. Delete hcloud.exe file

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The cache cleanup command is a recursive deletion operation, but it is scoped to a cache directory and therefore lower risk than deleting configuration or system paths. It is still destructive and should be accompanied by a warning that troubleshooting artifacts may be lost.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The cache cleanup command is a recursive deletion operation, but it is scoped to a cache directory and therefore lower risk than deleting configuration or system paths. It is still destructive and should be accompanied by a warning that troubleshooting artifacts may be lost.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 224)May include surrounding context.

Clean Cache

bash
# Clean KooCLI cache
rm -rf ~/.hcloud/cache/

# Clean downloaded files
rm -f hcloud_install.sh huaweicloud-cli-*.tar.gz huaweicloud-cli-*.zip

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples include broad natural-language phrases such as generic requests for help diagnosing failed or stuck jobs. In an agent environment, overly broad triggers can cause unintended invocation on loosely related conversations, potentially exposing cloud job metadata or logs to the skill when the user did not explicitly intend that workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The output template is explicitly defined in Chinese and the skill instructs the agent to generate reports strictly following that template. Elsewhere the document is primarily in English, but no user opt-in or locale selection is provided, so the skill effectively forces a specific language.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 338)May include surrounding context.

md
1. **Read-only throughout**: Only call GET APIs (except ListTrainingJobs which uses POST for read-only list query); never call Create/Update/Delete/Stop
2. **No credential leakage**: Never print AK/SK
3. **User confirmation required**: If fix suggestions involve changes (restart, modify specs), must clearly prompt "requires user confirmation before manual execution"; never auto-execute
4. **Sensitive information masking**: Logs may contain sensitive info; mask sensitive fields before output (e.g., desensitize IPs, do not print complete tokens)

### Scope Limitations

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document mandates diagnosis output headings in Chinese (## 诊断结论, ## 根因, ## 修复建议/## 后续步骤) as pass criteria. This is a natural-language locale requirement, and the file does not indicate user opt-in or explain why Chinese is required for a region-specific or compliance reason.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide recommends downloading and executing a remote shell script, including a non-interactive -y mode, without a prominent warning or integrity-verification step. This is dangerous because users may execute modified or compromised installer code directly on their system, potentially with elevated privileges in later troubleshooting steps.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The command fetches an external installer script from the network and immediately executes it locally. In the context of an installation guide, this behavior is expected, but it still introduces supply-chain risk if the remote resource or transport path is compromised.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The documented -y non-interactive install skips user confirmation, reducing friction but also removing a human checkpoint before executing installer actions. Combined with remote script execution, this makes accidental or automated unsafe deployment more likely.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

Download and run official installation script (interactive)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 49)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 73)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 181)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 54)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 78)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 157)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/cli-installation-guide.md:212