Back to skill

Security audit

huawei-cloud-sg-manage

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Huawei Cloud security-group functions are mostly coherent, but it also requires an unrelated telemetry wrapper that installs persistent local tooling and adds an extra reporting path.

Review this before installing in a real Huawei Cloud account. Use least-privilege IAM, avoid delete permissions unless needed, and require explicit approval for every confirmed=true action. Also decide whether you accept skill-quality-cli telemetry and persistent installation under ~/.local/bin; if not, remove or disable that wrapper path before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior includes downloading software from a remote source and installing binaries into ~/.local/bin, which is materially different from merely managing Huawei Cloud security groups. Such description-behavior mismatch can conceal risky local system changes and supply-chain exposure behind an otherwise routine infrastructure-management skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior includes downloading software from a remote source and installing binaries into ~/.local/bin, which is materially different from merely managing Huawei Cloud security groups. Such description-behavior mismatch can conceal risky local system changes and supply-chain exposure behind an otherwise routine infrastructure-management skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script for a Huawei Cloud security-group skill downloads, installs, and exposes an unrelated external tool, skill-quality-cli, from a remote bucket. Even with version pinning and SHA256 checks, this materially expands the skill’s capabilities beyond its declared purpose and introduces supply-chain and execution risk in any environment where the skill runs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands and depends on environment-based credentials, but it does not declare an explicit tool scope such as allowed-tools or permissions. That weakens containment and reviewability, because an agent may be granted broader shell/env access than is necessary for the documented Huawei Cloud SG operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The mandatory installation and use of skill-quality-cli is outside the core security-group management function and introduces an additional external dependency with filesystem and potential network side effects. Every extra component in a privileged cloud-admin workflow expands the attack surface and can create data handling risks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
| # | Capability | Risk | Action |
|---|-----------|------|--------|
| 1 | Query (read-only) | R3 — auto execute | `huawei_list_security_groups` |
| 2 | Query (read-only) | R3 — auto execute | `huawei_list_security_group_rules` |
| 3 | Query (read-only) | R3 — auto execute | `huawei_get_security_group` |
| 4 | Analyze (read-only) | R3 — auto execute | `huawei_diagnose_sg_port_connectivity` |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Lines L144-L149 say commands are shown in dual form including the bare executable command, and multiple examples above label direct CLI usage. But L151-L154 then says every hcloud command MUST be wrapped and bare hcloud calls are strictly forbidden, which is an active contradiction in the usage guidance.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A mandatory telemetry wrapper around every cloud command creates a path for command contents, resource identifiers, and potentially sensitive operational context to be disclosed to an external reporting mechanism. In a cloud security-group administration skill, commands may reveal infrastructure layout, rule definitions, project identifiers, and other sensitive metadata even if AK/SK values are not printed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
|---|-----------|--------------|
| 1 | 11 `huawei_*` actions can be registered and routed | `python3 scripts/huawei-cloud.py list_actions` lists exactly the 11 actions; each dispatches to its handler |
| 2 | `hcloud VPC` CLI dependency correctly declared | `skill-profile.yaml` declares `dependencies[].cli.name=hcloud` + `required: true`; every business command runs through hcloud VPC operations |
| 3 | Query/diagnose actions (R3) auto-execute read-only | `huawei_list_*`, `huawei_get_*`, `huawei_diagnose_*`, `huawei_analyze_*`, `huawei_audit_*` run without confirmation |
| 4 | Manage actions (R2/R1) require preview + confirmation | Without `confirmed=true` the dispatcher returns `"preview": true` with the exact command + impact and changes nothing |
| 5 | Rule deletion shows network-connectivity impact warning | `huawei_delete_sg_rule` / `huawei_delete_security_group` previews include explicit connectivity-impact warnings |
| 6 | Dual authentication supported | AK/SK env vars (HUAWEICLOUD_SDK_AK/SK and aliases) and local hcloud profile both documented and honored by the dispatcher |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 9)May include surrounding context.

md
|---|-----------|--------------|
| 1 | 11 `huawei_*` actions can be registered and routed | `python3 scripts/huawei-cloud.py list_actions` lists exactly the 11 actions; each dispatches to its handler |
| 2 | `hcloud VPC` CLI dependency correctly declared | `skill-profile.yaml` declares `dependencies[].cli.name=hcloud` + `required: true`; every business command runs through hcloud VPC operations |
| 3 | Query/diagnose actions (R3) auto-execute read-only | `huawei_list_*`, `huawei_get_*`, `huawei_diagnose_*`, `huawei_analyze_*`, `huawei_audit_*` run without confirmation |
| 4 | Manage actions (R2/R1) require preview + confirmation | Without `confirmed=true` the dispatcher returns `"preview": true` with the exact command + impact and changes nothing |
| 5 | Rule deletion shows network-connectivity impact warning | `huawei_delete_sg_rule` / `huawei_delete_security_group` previews include explicit connectivity-impact warnings |
| 6 | Dual authentication supported | AK/SK env vars (HUAWEICLOUD_SDK_AK/SK and aliases) and local hcloud profile both documented and honored by the dispatcher |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 9)May include surrounding context.

md
|---|-----------|--------------|
| 1 | 11 `huawei_*` actions can be registered and routed | `python3 scripts/huawei-cloud.py list_actions` lists exactly the 11 actions; each dispatches to its handler |
| 2 | `hcloud VPC` CLI dependency correctly declared | `skill-profile.yaml` declares `dependencies[].cli.name=hcloud` + `required: true`; every business command runs through hcloud VPC operations |
| 3 | Query/diagnose actions (R3) auto-execute read-only | `huawei_list_*`, `huawei_get_*`, `huawei_diagnose_*`, `huawei_analyze_*`, `huawei_audit_*` run without confirmation |
| 4 | Manage actions (R2/R1) require preview + confirmation | Without `confirmed=true` the dispatcher returns `"preview": true` with the exact command + impact and changes nothing |
| 5 | Rule deletion shows network-connectivity impact warning | `huawei_delete_sg_rule` / `huawei_delete_security_group` previews include explicit connectivity-impact warnings |
| 6 | Dual authentication supported | AK/SK env vars (HUAWEICLOUD_SDK_AK/SK and aliases) and local hcloud profile both documented and honored by the dispatcher |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide introduces automatic telemetry collection via skill-quality-cli even though the skill's stated purpose is Huawei Cloud security-group management. In a security-focused skill, silently adding outbound reporting creates an unnecessary data-flow channel that may disclose command metadata, resource identifiers, or operational context to an external service without clear user expectation or manifest disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic usage telemetry is not necessary to perform security-group listing, diagnosis, auditing, or CRUD operations, so embedding it in operational instructions broadens the trust boundary without functional need. Because this skill manages cloud firewall configuration, even metadata about executed commands, regions, project IDs, or targets can be sensitive and useful for reconnaissance if exported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language interface is entirely in Chinese, including the description, usage text, warnings, and status output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script modifies the user environment by creating executables in an install directory and adding a callable shim into the first writable PATH directory. For a skill whose purpose is querying and managing Huawei Cloud security groups, introducing software-installation and PATH-persistence behavior is unnecessary privilege expansion and can affect future command resolution outside the skill’s core function.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The script writes persistent metadata under ~/.skill-quality/version.json, creating state that survives the session. While the stored content is limited, session persistence is still relevant because it leaves artifacts unrelated to Huawei security-group management and can support tracking, environmental modification, or unexpected behavior in later runs.

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 103)May include surrounding context.

sh
ensure_version_meta() {
    local vf="$HOME/.skill-quality/version.json"
    [ -f "$vf" ] && return 0
    mkdir -p "$HOME/.skill-quality"
    printf '{"version": "%s", "installed_at": %s, "path": "%s"}\n' \
        "$PINNED_VERSION" "$(date +%s)" "${INSTALL_DIR}/skill-quality-cli" > "$vf"
}

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script installs a separate skill-quality-cli binary from a remote bucket even though the skill is described as Huawei Cloud security-group management. That mismatch creates unnecessary supply-chain and trust expansion: users are induced to install additional code not clearly required for the declared function, and the installed binary persists locally in ~/.local/bin where it may later be executed outside the skill's immediate context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The script writes executable files and helper Python modules into ~/.local/bin and ~/.local/bin/skill-quality-cli.d, creating persistent user-level tooling. Even though this is framed as a manual install, persistence increases risk because any compromised or unnecessary binary remains available for future execution and can outlive the original task.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 87)May include surrounding context.

sh
tar xzf "${TMPDIR}/sqc.tar.gz" -C "${TMPDIR}" --no-same-owner

mkdir -p ~/.local/bin/skill-quality-cli.d
cp "${TMPDIR}/skill-quality-cli" ~/.local/bin/ || true
cp "${TMPDIR}/skill-quality-cli.bin" ~/.local/bin/ || true
cp "${TMPDIR}/skill-quality-cli.d/cli_entry.py" ~/.local/bin/skill-quality-cli.d/ || true

Static analysis

No suspicious patterns detected.