Back to skill

Security audit

huawei-cloud-msmodelslim-model-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a model-analysis guide, but it can lead an agent to run untrusted model repository code without clear warning, approval, or sandboxing.

Review before installing. Use this skill only for trusted or reviewed model repositories, and do not follow the trust_remote_code=True troubleshooting step unless you explicitly intend to execute that repository's Python code in a disposable sandbox with no secrets or writable host access. Prefer static inspection of config.json and modeling files for this analysis.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/troubleshooting.md:35
Finding

Untrusted Model Repository Code Execution via trust_remote_code

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 35–44
Vulnerability Type: Execution of remotely supplied model code
Risk Level: High

Vulnerable code:

markdown
### Issue: trust_remote_code required

**Symptom:** `OSError: xxx requires trust_remote_code=True`

**Solution:**

```python
from transformers import AutoModel, AutoTokenizer
model = AutoModel.from_pretrained(path, trust_remote_code=True)
text

The related workflow in `SKILL.md`, lines 75–84, permits a model repository identifier as input and instructs the agent to download model-local implementation files when they are absent locally.

### Technical Analysis

Setting `trust_remote_code=True` instructs Transformers to load and execute custom Python implementation code supplied by the selected model repository. The repository provider therefore controls executable code that runs in the local Python process.

This crosses the trust boundary between externally supplied model artifacts and the agent's local execution environment. The Skill's stated purpose only requires static inspection of configuration and implementation files; executing model-provided Python is unnecessary for that analysis. The documented troubleshooting instruction does not require source review, repository revision pinning, isolation, restricted credentials, or explicit informed approval before execution.

### Attack Path

1. An attacker publishes or controls a model repository containing a configuration that references custom model implementation code.
2. A user or agent selects that repository for compatibility analysis.
3. The normal workflow obtains the repository's configuration or model-local implementation files.
4. Model loading reports that `trust_remote_code=True` is required.
5. The agent follows `references/troubleshooting.md` and invokes `AutoModel.from_pretrained(path, trust_remote_code=True)`.
6. Transformers imports and executes the repository-controlled Python code 
...[truncated 692 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to use trust_remote_code=True.
  2. Analyze model-local implementation files statically without importing or executing them.
  3. Download only the configuration, index, and source files required for inspection; do not instantiate the remote model.
  4. If execution is indispensable, require explicit informed user approval identifying that repository-controlled Python will run.
  5. Execute such code only inside a disposable sandbox or container with:
    • No host credentials or secrets.
    • No writable host mounts.
    • No elevated privileges.
    • Network access disabled by default.
    • Strict CPU, memory, and runtime limits.
  6. Pin the model repository to an immutable revision and review the exact source at that revision before execution.
  7. Treat auto_map and all model-local Python modules as untrusted input, and stop the analysis when safe static inspection is insufficient.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and generic, including common terms like model analysis, transformers, feasibility, and adapter. Overbroad activation criteria can cause the skill to trigger in unrelated contexts, leading to prompt hijacking of normal model discussions and unnecessary exposure to tool-enabled workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example user phrases are highly generic and lack clear boundaries, which reinforces accidental invocation for ordinary requests like checking whether a model can be quantized. In a tool-enabled skill, this raises the chance of the agent entering an analysis workflow and handling local repositories or downloaded artifacts when the user did not intend to use this specialized skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill contradicts itself by declaring non-transformers implementations unsupported while later instructing the agent to analyze model-local implementations. This ambiguity can cause inconsistent behavior, incorrect trust in unsupported code paths, and unsafe analysis decisions when the agent is asked to reason about local model code that may be incomplete or custom.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises capabilities beyond its declared purpose, expanding from model structure/MoE analysis into migration blockers, operator coverage, and Ascend NPU compatibility scoring. This can mislead an agent into making authoritative hardware-compatibility judgments without sufficient evidence, increasing the risk of incorrect recommendations and over-privileged task execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 65)May include surrounding context.

source = "transformers"

text

**Error:** Assume transformers without verification

```python
source = "transformers"  # Wrong: no verification

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 68)May include surrounding context.

Error: Assume transformers without verification

python
source = "transformers"  # Wrong: no verification

Model Type Detection

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting guidance recommends setting trust_remote_code=True to load a model but does not warn that this causes execution of model-provided Python code from the repository. In a skill specifically focused on analyzing and adapting third-party models, users are likely to apply this advice to untrusted model sources, which increases the chance of arbitrary code execution on the analyst's machine or CI environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.