Back to skill

Security audit

huawei-cloud-publish-work-to-gallery

Security checks for vulnerabilities and agentic risk

Overview

The skill’s publishing purpose is coherent, but it handles cloud credentials and recommends unsafe remote installer commands that deserve review before installation.

Install only if you are comfortable letting this skill use Huawei Cloud credentials, create short-lived STS credentials, submit a project, and expose a local app through DevBridge. Prefer a disposable dev environment, verify any remote installer before running it, keep screenshots limited to local project URLs, and delete temporary STS credential files after publishing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen_sts.py:84
Finding

Predictable and Insecurely Created Temporary STS Credential Files

Content
View full analysis

Vulnerability Details

File Location: scripts/gen_sts.py, lines 84–85 and 110–118
Vulnerability Type: Insecure temporary-file handling and plaintext credential exposure
Risk Level: Medium

Vulnerable Code

python
creds_out = args.creds_out or str(Path(tempfile.gettempdir()) / "sts-creds.json")
sh_out = args.sh_out or str(Path(tempfile.gettempdir()) / "sts-creds.sh")
python
camel = {
    "accessKeyId": c["credentials"]["access_key_id"],
    "secretAccessKey": c["credentials"]["secret_access_key"],
    "securityToken": c["credentials"]["security_token"],
    "_refresh": {"accountId": args.account, "agencyUrn": agency_urn, "region": args.region, "hcloudExe": hcloud_exe},
}
Path(creds_out).write_text(json.dumps(camel, indent=2, ensure_ascii=False), encoding="utf-8")
Path(sh_out).write_text(
    f"export STS_AK='{c['credentials']['access_key_id']}'\n"
    f"export STS_SK='{c['credentials']['secret_access_key']}'\n"
    f"export STS_TOKEN='{c['credentials']['security_token']}'\n",
    encoding="utf-8",
)

Technical Analysis

The default output paths are fixed, predictable names in the shared operating-system temporary directory: sts-creds.json and sts-creds.sh. Both files contain active STS access keys, secret keys, and security tokens in plaintext.

The files are written with Path.write_text(), which does not enforce owner-only permissions, exclusive creation, or symbolic-link rejection. The effective permissions depend on the process umask. On a multi-user system, a permissive umask may expose the credentials to another local account.

The predictable names also permit a local attacker to pre-create either path as a symbolic link. When the victim runs Step 1 of the documented publishing workflow, write_text() follows the link and truncates the linked destination if it is writable by the victim. This creates both a credential-disclosure opportunity and a limited arbitrary-file-overwrite primitive under the victim's pe ...[truncated 1476 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a unique private directory for each invocation using tempfile.mkdtemp() or tempfile.TemporaryDirectory(), and enforce mode 0700.
  2. Create credential files atomically with owner-only mode 0600, using os.open() with O_CREAT | O_EXCL; add O_NOFOLLOW where supported.
  3. Reject symbolic links and verify that any caller-supplied output target is a regular file in an authorized directory.
  4. Set restrictive permissions explicitly rather than relying on the process umask.
  5. Avoid generating sts-creds.sh unless it is strictly required. Prefer passing credentials through a protected file descriptor or private credential file.
  6. Delete temporary credential files in a finally block immediately after the publishing operation finishes or fails.
  7. Use unique filenames even inside the private directory to prevent collisions between concurrent executions.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (118)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Browser automation and screenshot generation are powerful primitives that exceed the minimum needed for many publishing tasks and can capture sensitive page contents if misdirected. Although likely intended for cover generation, the skill context makes these capabilities more dangerous because it also writes artifacts locally and can be paired with tunneling/execution steps.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
信号判定,**成功路径零源码读取**;失败才 `脚本提示 → troubleshooting 对应节 → grep 脚本源码` 逐级查 ② 禁止手工绕过门禁(`publish-work.mjs` 内置 `verifyGates()` 复核)③ 网络超时统一 3s ④ `detect-env.mjs` 确定平台后只读对应

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
信号判定,**成功路径零源码读取**;失败才 `脚本提示 → troubleshooting 对应节 → grep 脚本源码` 逐级查 ② 禁止手工绕过门禁(`publish-work.mjs` 内置 `verifyGates()` 复核)③ 网络超时统一 3s ④ `detect-env.mjs` 确定平台后只读对应

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
ep 脚本源码` 逐级查 ② 禁止手工绕过门禁(`publish-work.mjs` 内置 `verifyGates()` 复核)③ 网络超时统一 3s ④ `detect-env.mjs` 确定平台后只读对应平台 reference(按目录跳转,不全读)⑤ **合并无依赖的 bash 调用**:用 `;` 串联进一条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
| 4 | `preflight.sh` / `preflight.ps1` | 写 `font-gate-ok`(`ok=true gate=preflight`) | 截图/封面/图表**禁止** |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
| 4 | `preflight.sh` / `preflight.ps1` | 写 `font-gate-ok`(`ok=true gate=preflight`) | 截图/封面/图表**禁止** |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
| 4 | `preflight.sh` / `preflight.ps1` | 写 `font-gate-ok`(`ok=true gate=preflight`) | 截图/封面/图表**禁止** |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
| 4 | `preflight.sh` / `preflight.ps1` | 写 `font-gate-ok`(`ok=true gate=preflight`) | 截图/封面/图表**禁止** |

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill explicitly directs inspection of sensitive credential sources such as ~/.git-credentials, environment tokens, credential helpers, and Windows credential storage. Accessing or enumerating these secrets is dangerous because it can expose reusable authentication material unrelated to the immediate task, especially in an agentic environment with shell and file access.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
`gitUrl` 必填,`gitBranch` 必须显式读取。`workName` 从 README 解析/合成(<30 字符)。

1. `git -C <workDir> remote get-url origin` + `branch --show-current`。
2. **凭证排查**:`node <skill>/scripts/ensure-gitcode-credential.mjs`——自动检测本机 GitCode 凭证(`git credential fill`/`~/.git-credentials`/`$GITCODE_TOKEN`/`cmdkey`),无凭证时按平台给可行路径(Linux 提示手动配置 / Windows 检测 `gitcode-oauth` skill 并输出安装命令)。exit 0=有凭证或已有路径;exit 1=Windows 无凭证且 skill 未装(stderr 含安装命令 + Windows Git Bash 兼容提示)。
3. **凭证剥离**:`gitUrl="$(node <skill>/scripts/strip-git-credential.mjs "$(git remote get-url origin)")"`。硬校验:无 `@`、`https://` 开头、`.git` 结尾。
4. **命名**:`node <skill>/scripts/extract-workname.mjs <workDir>`——按优先级 frontmatter → H1 → manifest → `index.html <title>` → 目录名提取。stdout `#name=<name> source=<来源>`。`source=dirname` 时 agent 可合成/修改(<30 字符)。

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The document instructs users to fetch and immediately execute a remote shell script via curl ... | bash, which bypasses integrity review and gives the remote host full code execution on the user's system. In an agent/automation context, this is more dangerous because it normalizes unaudited code execution in headless environments and may run with elevated privileges.

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 8)May include surrounding context.

Linux / macOS

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

⚠️ headless 环境(无 tty)注意事项:

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping network-fetched content directly into bash is a classic dangerous command chain because it removes opportunities for validation and turns CDN or transport compromise into immediate shell execution. The skill context increases severity because users may follow these instructions in privileged, automated, or ephemeral environments where compromise can leak credentials or tamper with publication workflows.

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 8)May include surrounding context.

Linux / macOS

bash
curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash

⚠️ headless 环境(无 tty)注意事项:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 19)May include surrounding context.

md
> ```
> **解决方案**:先手动删除旧配置目录,再通过管道传入 `y` 绕过交互:
> ```bash
> rm -rf /root/.huawei/devbridge 2>/dev/null
> echo "y" | curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
> ```
> 若已存在预装的二进制(如 `/root/.huawei/bin/devbridge`),可直接复用,跳过安装。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 19)May include surrounding context.

md
> ```
> **解决方案**:先手动删除旧配置目录,再通过管道传入 `y` 绕过交互:
> ```bash
> rm -rf /root/.huawei/devbridge 2>/dev/null
> echo "y" | curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
> ```
> 若已存在预装的二进制(如 `/root/.huawei/bin/devbridge`),可直接复用,跳过安装。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 19)May include surrounding context.

md
> ```
> **解决方案**:先手动删除旧配置目录,再通过管道传入 `y` 绕过交互:
> ```bash
> rm -rf /root/.huawei/devbridge 2>/dev/null
> echo "y" | curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
> ```
> 若已存在预装的二进制(如 `/root/.huawei/bin/devbridge`),可直接复用,跳过安装。

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This repeats the same unsafe pattern and adds non-interactive execution (echo "y" | ... | bash), making unattended remote code execution even easier. In CI/AI DevSpace environments, this reduces human review and increases the chance that a compromised installer or CDN delivers arbitrary code automatically.

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 20)May include surrounding context.

md
> **解决方案**:先手动删除旧配置目录,再通过管道传入 `y` 绕过交互:
> ```bash
> rm -rf /root/.huawei/devbridge 2>/dev/null
> echo "y" | curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
> ```
> 若已存在预装的二进制(如 `/root/.huawei/bin/devbridge`),可直接复用,跳过安装。

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This command chain combines forced non-interactive input with direct execution of remote code, creating a highly automation-friendly unsafe pattern. If the remote script is malicious or tampered with, the command will execute it immediately without inspection, especially risky in CI, containers, or agent-driven workflows.

Content

Scanner excerpt · references/devbridge-tunnel.md (reported line 20)May include surrounding context.

md
> **解决方案**:先手动删除旧配置目录,再通过管道传入 `y` 绕过交互:
> ```bash
> rm -rf /root/.huawei/devbridge 2>/dev/null
> echo "y" | curl -fsSL https://res-hd.hc-cdn.cn/sharedata/hdspace/devbridge/install.sh | bash
> ```
> 若已存在预装的二进制(如 `/root/.huawei/bin/devbridge`),可直接复用,跳过安装。

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The document instructs users/agents to fetch a remote shell script with curl and immediately execute it via bash. Piping externally hosted installer logic into the shell without pinning, signature verification, or checksum validation is a classic supply-chain risk that could lead to arbitrary code execution if the remote resource is compromised or replaced.

Content

Scanner excerpt · references/troubleshooting.md (reported line 148)May include surrounding context.

bash
# Linux/macOS
curl -sSL https://res-hw-global.obs.ap-southeast-1.myhuaweicloud.com/cli/latest/hcloud_install.sh -o hcloud_install.sh && bash hcloud_install.sh
powershell

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/api.mjs:264

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build-cover.mjs:100

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build-detail-zip.mjs:144

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/check-version.mjs:49

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/detect-env.mjs:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/ensure-gitcode-credential.mjs:50

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publish-work.mjs:149

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/resolve-domain.mjs:75

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/ensure-gitcode-credential.mjs:59