Back to skill

Security audit

huawei-cloud-monitoring-query

Security checks for vulnerabilities and agentic risk

Overview

This Huawei Cloud query skill appears intended for read-only monitoring lookups, but its setup and network handling create serious credential and code-execution risk.

Review this before installing. Use only least-privileged Huawei Cloud credentials, avoid running it on sensitive machines, and do not run the setup path unless TLS verification and the remote get-pip.py bootstrap behavior are fixed or removed. The read-only query goal is reasonable, but the current package can expose authenticated cloud traffic to interception and can execute mutable remote setup code in a fallback path.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/ensure_env.py:278
Finding

Unverified Remote Bootstrap Script Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py, lines 27 and 278–294
Vulnerability Type: Remote code execution through an unauthenticated bootstrap download
Risk Level: Critical

Complete Code Snippet

python
ssl._create_default_https_context = ssl._create_unverified_context
python
get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py")
urls = [
    "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py",
    "https://bootstrap.pypa.io/get-pip.py",
]

ctx = ssl._create_unverified_context()

for url in urls:
    info(f"尝试下载 get-pip.py: {url}")
    try:
        urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    except Exception as e:
        print(f"    下载失败: {e}")
        continue

    rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)

Technical Analysis

The mandatory environment-preparation flow attempts to bootstrap pip when neither an existing pip installation nor ensurepip is available. It downloads get-pip.py from an external URL and immediately executes the downloaded file with the current Python interpreter.

The download explicitly uses ssl._create_unverified_context(). The module also globally replaces Python's default HTTPS context with an unverified context. Consequently, HTTPS encryption does not authenticate the remote endpoint: a forged, expired, or attacker-controlled certificate is accepted.

No signature, pinned digest, or other integrity check is applied before execution. The effective code executed by the Skill can therefore differ from the code reviewed in the project.

This path is reachable because SKILL.md requires the environment check before running queries, scripts/check_env.sh and scripts/check_env.ps1 invoke ensure_env.py, and _ensure_pip() uses this fallback when local bootstrap mechanisms fail.

Attack Path

  1. A user or Agent invokes the mandatory environment check.
  2. The environment lacks a functional ...[truncated 1290 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the global TLS override:
    python
    ssl._create_default_https_context = ssl._create_unverified_context
    
  2. Do not create or pass an unverified SSL context to urlretrieve. Use the platform trust store and fail closed on certificate errors.
  3. Prefer the standard ensurepip module or require administrators to install pip through a trusted system package manager rather than downloading executable bootstrap code.
  4. If remote bootstrap remains necessary:
    • Download only from a canonical HTTPS endpoint.
    • Verify a pinned SHA-256 digest or a trusted digital signature before execution.
    • Store the download in a securely created, process-private temporary file.
    • Refuse execution if any authenticity or integrity check fails.
  5. Avoid automatically executing mutable remote content during a mandatory Skill initialization path.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config.py:42
Finding

Huawei Cloud SDK Traffic Disables TLS Certificate Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py, lines 42–66
Vulnerability Type: Improper certificate validation for authenticated cloud API traffic
Risk Level: High

Complete Code Snippet

python
def build_http_config():
    """构建 HTTP 配置,代理支持环境变量

    代理 URL 来源(优先级从高到低):
      1. HTTPS_PROXY
      2. HTTP_PROXY

    代理 URL 格式:
      - http://host:port
      - http://user:pass@host:port
    """
    http_config = HttpConfig.get_default_config()
    http_config.ignore_ssl_verification = True
    http_config.timeout = (30, 60)
    http_config.retry_times = 3

    proxy_url = _get_proxy_url()
    if proxy_url:
        parsed = urlparse(proxy_url)
        http_config.proxy_protocol = parsed.scheme or "http"
        http_config.proxy_host = parsed.hostname or ""
        http_config.proxy_port = parsed.port or 8080
        http_config.proxy_user = parsed.username or ""
        http_config.proxy_password = parsed.password or ""

    return http_config

Technical Analysis

build_http_config() is used when constructing the Huawei Cloud CES, EPS, and IAM SDK clients. It unconditionally sets:

python
http_config.ignore_ssl_verification = True

This prevents the SDK from authenticating the TLS peer. An attacker capable of intercepting the connection can present an arbitrary certificate and impersonate a Huawei Cloud API endpoint. The same configuration also accepts proxy settings from HTTPS_PROXY or HTTP_PROXY, including plaintext HTTP proxy URLs.

The query scripts load Huawei Cloud credentials and attach them to SDK clients configured through this function. Although the secret key itself is used for request signing rather than intentionally transmitted as plaintext, intercepted traffic exposes signed authentication material, request metadata, and returned cloud-resource information. A man-in-the-middle endpoint can also forge API responses consumed and displayed by the Skill.

The proxy variables are ordinary environm ...[truncated 1752 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the ignore_ssl_verification = True assignment and retain certificate verification by default.
  2. Fail closed when endpoint certificate validation fails; do not silently retry with verification disabled.
  3. For enterprise TLS interception, support an explicitly configured CA bundle instead of globally bypassing authentication.
  4. Require authenticated, encrypted proxy configurations for credential-bearing cloud requests. Reject unsupported or insecure proxy schemes where appropriate.
  5. Validate proxy configuration and avoid embedding proxy credentials in logs or error messages.
  6. Add automated tests confirming that invalid, self-signed, expired, and hostname-mismatched certificates are rejected.
  7. Apply the corrected HTTP configuration consistently to every CES, EPS, and IAM client.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Using IAM project-listing and project-ID lookup is not inherently unsafe, but it materially expands the capability surface beyond the declared CES/EPS monitoring focus. In context, this hidden scope expansion is risky because it normalizes broader account discovery and metadata access under a narrowly described skill, which can leak inventory structure and weaken least-privilege assumptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Using IAM project-listing and project-ID lookup is not inherently unsafe, but it materially expands the capability surface beyond the declared CES/EPS monitoring focus. In context, this hidden scope expansion is risky because it normalizes broader account discovery and metadata access under a narrowly described skill, which can leak inventory structure and weaken least-privilege assumptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Using IAM project-listing and project-ID lookup is not inherently unsafe, but it materially expands the capability surface beyond the declared CES/EPS monitoring focus. In context, this hidden scope expansion is risky because it normalizes broader account discovery and metadata access under a narrowly described skill, which can leak inventory structure and weaken least-privilege assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The body of the skill describes a broad cloud resource inventory/query framework rather than a narrowly scoped CES/EPS monitoring skill. This scope inflation is dangerous because it can mislead users, reviewers, and policy controls into approving a much more powerful capability set than intended, including discovery of unrelated infrastructure and dependencies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented capability scope expands into generic infrastructure selection, inventory, and dependency relationship discovery, which exceeds a monitoring/EPS-only mandate. In a credentialed cloud environment, that broader discovery surface can expose sensitive topology, identifiers, and asset relationships useful for reconnaissance or follow-on abuse.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云资源查询 - 环境检查前置脚本 (Windows PowerShell)
#>

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code explicitly disables TLS certificate verification with http_config.ignore_ssl_verification = True and suppresses the resulting warning, which permits man-in-the-middle interception of traffic to Huawei Cloud endpoints or configured proxies. Because this skill handles cloud credentials and supports proxy-based outbound connections, an attacker controlling the network path or proxy could capture credentials, alter responses, or redirect requests without detection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script globally disables TLS certificate verification via ssl._create_default_https_context and also uses an unverified SSL context for bootstrap downloads. This allows man-in-the-middle interception of package downloads and API traffic, enabling dependency tampering, credential exposure, or false service responses.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 69)May include surrounding context.

python
# 用 venv Python 重新执行当前脚本
    print(f"  使用虚拟环境 Python: {venv_python}")
    os.execv(venv_python, [venv_python] + sys.argv)

def info(msg):
    print(f"  {msg}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly directs execution of local shell and Python commands and relies on environment variables and network access, yet it declares no explicit tool scope or permission boundaries. In an agent setting, this creates an over-privileged execution surface where a seemingly read-only cloud query skill can invoke arbitrary local scripts, inspect credentials, and reach external services without transparent restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation starts from a Huawei monitoring/EPS framing but immediately introduces unrelated generic resource categories and examples, creating ambiguity about what the skill truly does. Ambiguous security boundaries are dangerous in agent ecosystems because they encourage overbroad invocation and make it harder to apply least privilege and review hidden functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

At L13 the script loads AK/SK/security token credentials, which is a sensitive operation covered by the missing-warning rule for code files. While the script prints query results and errors, it provides no confirmation, log, comment, or docstring disclosing that it will access cloud credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script loads access credentials at L13 and uses them to build an authenticated CES client and call the remote API at L34-L40. While the command purpose is described, there is no explicit warning, confirmation, or disclosure that running it will use configured credentials and transmit request data to Huawei Cloud.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argparse description and help text are written only in Chinese, and additional runtime messages later in the file follow the same pattern. This forces a specific language for all users without opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This PowerShell script presents its title, status messages, and failure guidance exclusively in Chinese, which constitutes a natural-language locale constraint visible in the file. The file does not offer user opt-in for language selection or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 40)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 187)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 188)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code loads cloud access credentials and an optional security token from environment variables, which is a sensitive operation under the review criteria. Although the docstring explains how the variables are used, it does not warn users that the skill accesses credential material or that these values may be used for authenticated cloud requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing messages are written only in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the policy for natural-language violations, a forced locale/language is reportable unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 129)May include surrounding context.

python
# ── 工具函数 ──────────────────────────────────────────────────────────

def run_cmd(cmd, timeout=None, **kwargs):
    """运行命令,返回 (returncode, stdout, stderr)

    Args:

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ensure_env.py:284