Back to skill

Security audit

huawei-cloud-modelarts-training-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent Huawei Cloud ModelArts management helper, but it asks users to grant broad cloud authority and includes unsafe installer and credential-fallback guidance that should be reviewed carefully.

Install only if you are comfortable giving an agent-assisted workflow access to Huawei Cloud ModelArts resources. Prefer a minimal or read-only IAM policy first, avoid the one-line remote installer unless you verify the source, do not pass AK/SK secrets through chat or command-line history, and require explicit confirmation before any create, delete, stop, agency, scheduled-event, or billable operation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad ModelArts lifecycle management, but the documented behavior also introduces undeclared billing and IAM project lookup flows while not actually specifying concrete safe execution logic for the claimed operations. This mismatch is dangerous because users and orchestrators may grant trust or permissions based on the declared purpose, while the actual behavior touches additional sensitive domains such as billing metadata and project enumeration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The SDK fallback instructs the agent to instantiate credentials with raw AK and SK values inside the session, directly contradicting the earlier rule that the agent must never handle or expose secrets. This creates a clear path for secret collection, accidental logging, prompt leakage, or transmission of credentials through agent tooling.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This command fetches an installer from the network and immediately executes it with bash, eliminating any opportunity to verify integrity or inspect behavior first. In a skill that manages cloud training infrastructure, compromise of the installer could lead to local code execution, credential theft, or tampering with cloud management operations.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

Method 1: One-line Install (Recommended)

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Default install path: /usr/local/hcloud/, symlinked to /usr/local/bin/hcloud.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This variant repeats the same remote-script execution pattern while also encouraging non-interactive acceptance of defaults, increasing the chance that users will run it without review. If abused, it could silently install or alter binaries and paths in a way that facilitates persistent compromise or credential interception.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 25)May include surrounding context.

To skip interactive prompts with defaults:

bash
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

Method 2: Step-by-step Install

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The non-interactive authentication example places access key and secret key values directly on the command line, which can be exposed through shell history, process listings, logging, or CI job output. Because these are cloud credentials, leakage could enable unauthorized access to ModelArts and potentially other Huawei Cloud resources accessible to that principal.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill declares powerful operational behavior through CLI usage but does not define an explicit tool scope such as allowed tools or permissions. In an agent setting, this weakens containment and can allow unintended access to environment-derived data or broader execution capabilities than the user expects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "huawei-cloud-modelarts-training-management"
description: "Manage Huawei Cloud ModelArts training jobs and related resources through full lifecycle operations via hcloud CLI. Covers 52 API interfaces across 8 functional domains: training job management, algorithm management, training job tags, training experiments, training job events, model import, auto search (hyperparameter tuning), and training image save. All write operations require user confirmation before execution. Triggers include: \"ModelArts training\", \"训练作业\", \"模型训练\", \"创建训练作业\", \"查询训练作业\", \"停止训练作业\", \"删除训练作业\", \"算法管理\", \"超参配置\", \"training job\", \"training management\", \"create training\", \"ModelArts 训练\", \"训练实验\", \"自动搜索\", \"超参调优\"."
---

# Huawei Cloud ModelArts Training Management

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown hardcodes the BSS API region to cn-north-1, which imposes a specific regional/locale setting in the workflow text. Because the document does not present this as a user-selectable option or clearly justify it as a region-specific compliance/technical requirement, it reads as a locale constraint that may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents multiple state-changing and destructive operations such as StopTrainingJob, DeleteTrainingJob, DeleteAlgorithm, DeleteTrainingExperiment, DeleteModel, and early-stop actions, but it provides no warning that these actions can stop jobs or permanently remove resources. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents a query operation that returns instance IP, node IP, and scheduling information, which can expose infrastructure details. The description includes no warning about the sensitivity of this metadata or guidance to avoid sharing it broadly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest scopes the skill to ModelArts training jobs and related training resources such as algorithms, experiments, events, model import, auto search, and image save. Creating a ModelArts IAM agency is an account-level identity/permission-management action, which is not obviously part of training lifecycle management and grants cross-service access to OBS and other services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide recommends downloading and executing a remote shell script and notes installation into privileged system paths, but does not warn users that this grants the script broad control over the host. If the hosting location, network path, or script content is compromised, users could unknowingly execute arbitrary code with elevated privileges.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes coverage across eight ModelArts training-related domains, including training job events, but does not mention broader system event management. This diagram adds 'System' event capabilities such as ListEvents, ListEventCategories, ListScheduledEvents, and AcceptScheduledEvent, which appear outside the stated ModelArts training-management scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The combined IAM policy grants wildcard permissions across multiple ModelArts domains and uses "Resource": "*", which enables broad destructive and administrative actions such as deleting training jobs, models, algorithms, and accepting scheduled events. In a skill intended to manage full lifecycle training resources, publishing this as an example without a prominent warning or stronger least-privilege guidance increases the chance that users deploy overprivileged credentials and expose their environment to accidental or malicious misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes a workaround that instructs users to load AK/SK credentials from environment variables, which is a sensitive operation affecting secret handling. The surrounding documentation provides no warning about protecting these variables, avoiding shell history leakage, or using secure secret management.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes lifecycle management of ModelArts training jobs and related ModelArts resources across eight ModelArts domains, but this file instructs the agent to call separate BSS pricing APIs and IAM project-listing APIs before execution. Billing inquiry is a distinct capability not mentioned in the manifest description, so the documented behavior exceeds the declared scope rather than being an obvious implementation detail of training-job management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example sets REGION="cn-north-4", which imposes a specific locale/region in natural-language guidance and command examples. The file does not offer an opt-in choice or explain that the region is only an example, so it can conflict with language/locale policy requiring user choice or justified constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes lifecycle management of ModelArts training jobs and related resources across eight domains, but does not include pricing, billing, or BSS quotation functionality. This script is explicitly an on-demand pricing helper and calls the BSS pricing API, which is a different functional area than training-job management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All usage text, help output, status messages, and result formatting are hard-coded in Chinese, and there is no option for the user to select another language. The provided file does not document that the skill is intentionally limited to a Chinese-speaking or region-specific audience beyond the cloud region parameters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This acceptance criterion mandates that each API description be provided in Chinese and English. Under the stated policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest states the skill manages resources 'via hcloud CLI' and emphasizes CLI-based lifecycle operations. The diagram introduces an 'SDK Fallback' path on CLI bug, which suggests an alternative implementation path that contradicts the documented CLI-only operating model.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill for managing Huawei Cloud ModelArts training jobs and related ModelArts resources via hcloud CLI. This file documents use of hcloud OBS ListObjects, which is an OBS storage operation rather than a ModelArts training-management operation, and that capability is not explicitly declared in the manifest scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The workflow directs the agent to call IAM KeystoneListAuthProjects to enumerate projects and derive a project ID for pricing requests. IAM project enumeration is not part of the manifest’s stated ModelArts training-management domains and is a separate account-discovery capability only justified here by the added billing feature, not by training management itself.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The FAQ states that the skill currently supports only on-demand pricing inquiry, which reframes part of the skill as a billing/pricing tool rather than purely a training-management tool. That documented capability is not reflected in the manifest’s declared functional domains, creating a semantic mismatch in stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This shell script depends on an already authenticated hcloud CLI and later sends project and pricing query data to remote IAM/BSS APIs. Although the script logs progress, it does not clearly warn the user that running it will use configured cloud credentials and transmit request data to external services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.