Back to skill

Security audit

huawei-cloud-msmodelslim-model-adapt

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for msModelSlim adapter work, but it repeatedly enables model-supplied code execution by default without clear warnings or user opt-in.

Install only if you are comfortable running model-loading and quantization code locally. Use this skill with trusted, pinned model repositories or reviewed local model files, avoid enabling remote code for untrusted models, prefer safetensors over pytorch_model.bin, and review any install.sh effects before running registration steps.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes building msModelSlim adapters for Transformers models and completing a quantization-oriented verification workflow. The supplied code does not implement quantization, verification, model generation, or validation steps. Instead, it performs a specific model-structure transformation for Mixture-of-Experts weights: identifying packed expert tensors, unpacking them into per-expert linear weights, swapping in a different MoE block class, and loading the resulting state dict. While this could be a supporting piece inside an adapter, the chunk’s primary behavior is materially different and much narrower than the declared end-to-end adapter/quantization workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on building msModelSlim adapters and executing a quantization-oriented verification pipeline for Transformers models. In contrast, the supplied code only defines PyTorch modules for an MoE block with explicit linear experts and routing. While it could be tangentially useful as an adaptation example for certain model internals, it does not implement the claimed adapter interfaces, quantization workflow, or validation steps. The primary purpose is materially different from the declared one, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command enables --trust_remote_code True, which permits execution of model-supplied Python code during loading or quantization. In a skill focused on adapting arbitrary third-party models, this materially increases risk because users may run untrusted repositories or model packages without any warning, isolation guidance, or approval checkpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This second quantization example repeats the same unsafe pattern by enabling --trust_remote_code True for another execution path. Because the guide presents this as normal verification procedure, it normalizes risky behavior and can lead to arbitrary code execution when processing untrusted or compromised model artifacts.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script always passes --trust_remote_code True to msmodelslim, which can cause loading and execution of Python code supplied by a remote or untrusted model repository during quantization. In this skill context, users are adapting arbitrary LLM/VLM models, so enabling remote code execution by default significantly increases the risk of arbitrary code execution on the host running the workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list is very broad and includes generic terms like 'adapter', 'quantization', 'transformers', 'LLM', and 'VLM', which can cause the skill to activate in unrelated contexts. Unintended invocation can route users into running unnecessary shell/python steps or following the wrong workflow, increasing the chance of unsafe command execution or misuse of local model files in an automated agent setting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L15 tells the user to run bash install.sh, which is a subprocess/shell execution step. The document provides no warning or disclosure about what the script changes, installs, or whether it modifies the local system, so users are not informed about a potentially system-affecting action.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The troubleshooting guidance explicitly instructs users to set trust_remote_code=True when loading a model, which allows execution of arbitrary Python code supplied by the model repository. In the context of a model-adapter and quantization skill, this expands execution beyond the intended local adapter workflow and can lead to code execution if users load an untrusted or compromised model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown guide describes a "CoreVerificationProcess" that "must" be executed in order, but it does not define when this verification flow should be used versus when it should not. The absence of explicit applicability boundaries, trigger conditions, or exclusion examples makes the activation scope of the guide ambiguous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using from_config(..., trust_remote_code=True) permits loading and executing custom model code from a model repository or local model package, which can run arbitrary Python during adapter generation. In this skill context, users are expected to point the script at model artifacts, so a malicious or untrusted model path could turn a routine quantization workflow into code execution on the host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

AutoConfig.from_pretrained(..., trust_remote_code=True) can also trigger execution of repository-provided custom configuration code, expanding the attack surface before model instantiation even occurs. Because this script processes arbitrary model paths for adapter creation, the skill context makes this more dangerous: model ingestion is a primary feature, so attacker-supplied model repos are a realistic input channel.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/step2_run_quantization.py (reported line 98)May include surrounding context.

python
"--trust_remote_code",
        "True",
    ]
    rc = subprocess.run(cmd, check=False).returncode
    if rc != 0:
        print("[ERROR] step2lossfailure")
        return rc

Insecure deserialization: torch.load() without weights_only=True

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script calls torch.load() on a file path derived from user-supplied model directories. torch.load uses Python pickle for legacy .bin checkpoints, which can execute arbitrary code during deserialization if a malicious pytorch_model.bin is provided. In this skill, the script is explicitly meant to ingest external model artifacts for adapter and quantization workflows, which increases exposure because untrusted or third-party model directories are a realistic input source.

Content

Scanner excerpt · scripts/step3_verify_weights.py (reported line 27)May include surrounding context.

python
pt_path = os.path.join(model_path, "pytorch_model.bin")
    if os.path.exists(pt_path):
        return torch.load(pt_path, map_location="cpu")
    return {}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This Python file contains hard-coded user-facing strings, comments, and argument descriptions in a mixed/nonstandard language form throughout the script, with no option to select locale or fall back to the user's preferred language. That can violate language/locale policy when tools are expected to be understandable or locale-neutral unless a specific locale is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/step1_generate_test_model.py (reported line 62)May include surrounding context.

python
]
    errors = []
    for cls_name in candidate_auto_model_names:
        auto_cls = getattr(transformers, cls_name, None)
        if auto_cls is None:
            continue
        try:

Static analysis

No suspicious patterns detected.