Back to skill

Security audit

huawei-cloud-msot-msopprof-operator-profiler

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Ascend NPU profiling aid, but some troubleshooting commands weaken host security more than the profiling task requires.

Review this skill before installing on shared, production, or security-hardened hosts. Avoid following the setenforce 0 and chmod 777 examples as written; use a private user-owned output directory, least-privilege permissions, and SELinux label or policy troubleshooting instead. Treat generated profiling reports and CSVs as potentially confidential.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/troubleshooting.md:24
Finding

Troubleshooting guidance disables SELinux enforcement system-wide

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 24–26
Vulnerability Type: Host-wide mandatory access-control weakening
Risk Level: High

Vulnerable snippet:

bash
# Check SELinux (if applicable)
getenforce
setenforce 0  # Temporarily disable if needed

Technical Analysis

The troubleshooting procedure recommends running setenforce 0 in response to an operator permission error. This switches SELinux into permissive mode for the entire host rather than addressing the specific denial through correct labels, file permissions, or a narrowly scoped policy.

The profiling task only requires access to a particular operator executable and output location. Disabling a host-wide mandatory access-control mechanism therefore exceeds the permissions legitimately required for the task. The instructions provide no mandatory administrator confirmation, isolated-environment requirement, or restoration command.

Exploitation requires the user to follow this guidance with sufficient administrative privileges. While SELinux remains permissive, an untrusted operator executable or another process on the host can attempt actions that the active SELinux policy would otherwise deny.

Attack Path

  1. The user encounters Permission denied while attempting to profile an operator.
  2. Following the Skill's troubleshooting instructions, the user invokes setenforce 0 with administrative privileges.
  3. SELinux stops enforcing policy across the entire host.
  4. The user executes the operator during profiling, or another local process runs while enforcement remains disabled.
  5. A malicious or compromised process performs operations that would ordinarily be blocked by SELinux.
  6. Because the procedure contains no restoration step, the weakened security state may persist until manually corrected or the host is rebooted.

Impact Assessment

The command does not itself grant root privileg ...[truncated 516 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to run setenforce 0.
  • Diagnose the denial using SELinux audit records, such as ausearch -m AVC, and identify the exact resource and policy rule involved.
  • Correct file ownership, permissions, or SELinux labels where they are inaccurate.
  • If policy changes are necessary, create a narrowly scoped rule for the specific executable and required resources rather than disabling enforcement globally.
  • If permissive-mode testing is unavoidable, require explicit administrator confirmation, use an isolated non-production host, limit the test duration, and restore enforcement with setenforce 1 immediately afterward.
  • Verify the final state with getenforce.

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting.md:115
Finding

Profiling output directory is made world-writable

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 115–117
Vulnerability Type: Insecure shared-directory permissions
Risk Level: Medium

Vulnerable snippet:

bash
# Check directory permissions
mkdir -p /tmp/profiling
chmod 777 /tmp/profiling

Technical Analysis

The troubleshooting guidance creates a predictable directory under /tmp and assigns mode 0777. Every local account can consequently read, create, modify, rename, and delete directory entries. Unlike a conventional shared temporary directory, this directory is not assigned a sticky bit.

Profiling tools subsequently using /tmp/profiling cross a local-user trust boundary: output expected to be controlled by the profiling user can instead be manipulated by any other local user. Depending on the profiling tool's file-creation and replacement behavior, an attacker can inject fabricated artifacts, delete results, or race the profiler when it creates output files.

Exploitation requires another local account or process with access to the same host. The finding does not rely on the profiling user intentionally supplying a malicious path.

Attack Path

  1. The profiling user follows the troubleshooting procedure and creates /tmp/profiling with mode 0777.
  2. A different local user observes or anticipates the predictable output location.
  3. Before or during profiling, that user creates, replaces, or removes entries within the directory.
  4. The profiling tool writes into or reads from the attacker-influenced directory.
  5. Subsequent analysis consumes corrupted or attacker-injected profiling artifacts, or legitimate profiling results are destroyed.
  6. If generated files are readable by other users, profiling information may additionally be exposed across local accounts.

Impact Assessment

A local attacker can compromise the integrity and availability of profiling output. This can lead to fabricated per ...[truncated 415 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the shared directory with a private, user-owned directory:
    bash
    mkdir -m 700 /tmp/profiling
    
  • Prefer a directory under the user's private application-data or working directory rather than a predictable global temporary path.
  • Verify that the destination is owned by the invoking user and is not a symbolic link before profiling.
  • For temporary output, use a securely generated directory such as one created by mktemp -d, and remove it when no longer needed.
  • If results must be shared, use a dedicated group and narrowly scoped group permissions such as 0750 or 0770, depending on the required write access.
  • Do not use chmod 777 as a generic remedy for permission errors.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The guidance abuses a filesystem permission tool by proposing a blanket permissive mode to solve a routine output-path problem. In a profiling skill, users are likely to run commands on development servers or shared AI systems, so normalizing 777 increases the chance of unsafe deployment practices and exploitable writable locations.

Content

Scanner excerpt · references/troubleshooting.md (reported line 143)May include surrounding context.

Check directory permissions

mkdir -p /tmp/profiling chmod 777 /tmp/profiling

text

### Issue: CSV files missing

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list contains broad terms like "profiler," "performance profiling," and "profile data," which can cause the skill to activate for generic profiling requests outside the Ascend/msopprof context. This can lead to inappropriate tool selection and execution in the wrong environment, increasing the chance of collecting unintended data or confusing users into using a specialized NPU profiling workflow for unrelated tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes collecting, generating, and exporting profiling data without warning that outputs may include sensitive model structure, operator names, file paths, runtime characteristics, and system performance details. In shared or less controlled environments, these artifacts can expose proprietary model information or operational telemetry that could aid reverse engineering or leak internal infrastructure details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting guidance suggests disabling SELinux with setenforce 0 as a temporary fix, but provides no warning about the security consequences or safer alternatives. Reducing or disabling a mandatory access control system weakens host protections and may expose unrelated services or files if users apply the advice broadly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 30)May include surrounding context.

bash
# Fix permissions
chmod 755 ./execute_op

# Check SELinux (if applicable)
getenforce

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document recommends chmod 777 /tmp/profiling to fix output directory issues, which makes the directory world-writable without any caution. On multi-user systems this can enable tampering, symlink attacks, data corruption, or unauthorized access to profiling artifacts, especially because /tmp is shared and commonly targeted.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

chmod 777 /tmp/profiling grants read, write, and execute permissions to all users, which is excessive for profiling output storage. In the context of troubleshooting on shared Linux hosts, this can allow unauthorized modification or replacement of files and can facilitate race-condition or symlink-based abuse.

Content

Scanner excerpt · references/troubleshooting.md (reported line 143)May include surrounding context.

Check directory permissions

mkdir -p /tmp/profiling chmod 777 /tmp/profiling

text

### Issue: CSV files missing

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The verification script includes an unconditional rm -rf output_npu before running profiling. Although limited to a relative directory name and likely intended as cleanup, it is still a destructive operation with no confirmation, backup, or safety guard, so users could lose existing profiling artifacts or unrelated data if the path is changed or run from an unexpected working directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.