Back to skill

Security audit

huawei-cloud-mrs-redis-meta-check

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Redis metadata checker, but it also gives production repair commands that can stop services and mutate or delete Redis metadata despite framing itself as static analysis.

Install only if you want a Redis metadata diagnostic skill that may also suggest manual production repair steps. Treat any stop, mv, cp, edit, or rm command it prints as operator guidance requiring independent validation, current backups, and explicit approval before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The skill includes a force-delete command (rm -f) targeting a metadata backup file on a cluster host. In agentic or copy-paste-driven environments, destructive shell commands are high risk because path mistakes, variable substitution errors, or misplaced automation can permanently remove recovery artifacts and worsen outage response.

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

  1. Confirm recovery: Instance status returns to Good and the Redis logical cluster status returns to normal
  2. Clean up the backup file (on the host):
    bash
    rm -f /srv/BigData/redis_meta/Redis_1/nodes-22400.conf_bak
    

7. Parameters

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L007 says to use the skill whenever the user asks about Redis startup failures or connection anomalies. Those symptoms can stem from many causes unrelated to nodes-*.conf metadata, so the trigger overlaps with broad operational troubleshooting language and lacks exclusion conditions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document says the skill cannot execute host commands, but later instructs operators to run shell commands such as ls, su, mv, cp, and rm on cluster hosts. This inconsistency is dangerous because it can cause an orchestrating agent or user to underestimate operational risk and follow host-level instructions under the assumption the workflow is non-executing and low risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as a static, read-only checker, but it also embeds step-by-step repair actions that rename, copy, edit, and delete Redis metadata files on production hosts. This creates a trust-boundary violation: a user or downstream agent may treat the skill as safe diagnostics while being steered into state-changing operations that can damage cluster metadata or availability if applied incorrectly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file includes Chinese-only trigger phrases such as "Redis元数据检查" and "Redis启动失败排查" alongside English content, but it does not state that language selection is optional or user-driven. This can create a locale expectation without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.