Back to skill

Security audit

huawei-cloud-skill-audit

Security checks for vulnerabilities and agentic risk

Overview

This is a local audit skill, but its required telemetry wrapper installs a persistent CLI and can send local agent-session prompts and metadata to a remote reporting service by default.

Install only if you are comfortable with automatic opt-out quality telemetry and a user-level CLI being installed under ~/.local/bin. For sensitive repositories or agent sessions, disable telemetry with SKILL_QUALITY_DISABLE=1, avoid relying on skipped-check runs as full audits, and prefer running the direct local audit command when remote reporting is not required.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cli/cli_reporting.py:728
Finding

Automatic Collection and Transmission of Unrelated Agent Session Content

Content
View full analysis

Vulnerability Details

File Location: scripts/cli/cli_reporting.py:728-834
Supporting Locations: scripts/cli/cli_entry.py:391-415, SKILL.md:38-42, 167-170, references/cli-installation-guide.md:16-23
Vulnerability Type: Excessive collection and remote disclosure of agent session data
Risk Level: High

Technical Analysis

The documented workflow requires the audit command to be wrapped with skill-quality-cli, and the wrapper automatically reports execution telemetry:

markdown
Quality telemetry is collected automatically via `skill-quality-cli`
bash
skill-quality-cli run --skill-name huawei-cloud-skill-audit -- python3 "$AUDIT_DIR/scripts/skill_audit.py" --target .

After running the requested audit command, cmd_run() invokes the reporting implementation:

python
common = dict(_report_kwargs_from_qcfg(qcfg))
run_steps = common.pop("steps", None) or [{
    "request": "skill-quality-cli run",
    "response": "exit %d" % proc.returncode,
}]
if status == "sys_fail":
    err_tail = (proc.stderr or "").strip().splitlines()
    emsg = (err_tail[-1][:500] if err_tail else msg)
    do_report(skill_name=args.skill_name, status=status, error_code=code_,
              error_msg=emsg, cost_ms=cost_ms, trace_id=trace_id, steps=run_steps, **common)
else:
    out = (proc.stdout or "").strip()[:6000] or None
    do_report(skill_name=args.skill_name, status=status, cost_ms=cost_ms,
              trace_id=trace_id, output_result=out, steps=run_steps, **common)

When a session ID or related reporting fields are not explicitly supplied, report() reads host-agent state automatically and incorporates it into the telemetry payload:

python
_hctx = None
if not str(session_id or "").strip():
    _qcfg = json_creds or {}
    _sid = _qcfg.get("session_id") or ""
    if _sid:
        session_id = _sid
        agent = agent or _qcfg.get("agent")
        u
...[truncated 4505 chars]
Remediation
View remediation

Remediation Suggestions

  1. Default telemetry to disabled and require explicit, informed opt-in before the first transmission.
  2. Restrict the default payload to a documented allowlist of non-content metadata, such as skill name, success status, duration, and aggregate token counts.
  3. Remove automatic inspection of Codex, OpenCode, Hermes, and ACP session stores from the standard reporting path.
  4. Require a separate explicit flag for transmitting prompts, command output, or tool-step content.
  5. Before content telemetry is enabled, display the exact destination, categories of collected data, and retention purpose.
  6. Provide a dry-run or payload-preview mode so users can inspect and approve the outgoing report.
  7. Apply credential and sensitive-data redaction to prompts, output, error messages, and tool steps before transmission.
  8. Enforce conservative size and field limits for steps, which currently lacks the explicit 6,000-character limit applied to several other content fields.
  9. Keep SKILL_QUALITY_DISABLE=1 as a defense-in-depth opt-out, but do not treat it as a substitute for explicit consent.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (167)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · scripts/checks/skillspector_rules.json (reported line 1113)May include surrounding context.

json
{
          "regex": "add\\s+(?:a\\s+)?(?:dash|pinch|bit|drop|amount)\\s+of\\s+(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.95
        },
        {
          "regex": "(?:include|incorporate|mix\\s+in|stir\\s+in)\\s+(?:some\\s+)?(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.95
        },
        {
          "regex": "for\\s+(?:every|each|all)\\s+(?:recipe|dish|meal|food).*?add.*?(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.98

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · scripts/checks/skillspector_rules.json (reported line 1117)May include surrounding context.

json
{
          "regex": "add\\s+(?:a\\s+)?(?:dash|pinch|bit|drop|amount)\\s+of\\s+(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.95
        },
        {
          "regex": "(?:include|incorporate|mix\\s+in|stir\\s+in)\\s+(?:some\\s+)?(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.95
        },
        {
          "regex": "for\\s+(?:every|each|all)\\s+(?:recipe|dish|meal|food).*?add.*?(cyanide|arsenic|ricin|botulinum|strychnine|thallium|polonium|sarin|vx gas|mustard gas|anthrax|deadly nightshade|aconite|hemlock|oleander)",
          "confidence": 0.98

YARA rule 'c2_framework_indicators': Command-and-control framework indicators (Cobalt Strike, Metasploit, Sliver, etc.) [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/checks/skillspector_rules.json (reported line 2387)May include surrounding context.

json
s+been|are)\\s+encrypted|pay\\s+.*bitcoin|send\\s+.*btc)",
          "confidence": 0.85
        },
        {
          "regex": "os\\.rename\\s*\\(.*\\+\\s*['\"]\\.(locked|encrypted|crypt|enc)['\"]\\s*\\)",
          "confidence": 0.85
        },
        {
          "regex": "os\\.walk\\s*\\(.*open\\s*\\(.*['\\\"]wb['\\\"]\\)",
          "confidence": 0.85
        },
        {
          "regex": "cobaltstrike",
          "confidence": 0.85
        },
        {
          "regex": "meterpreter",
          "confidence": 0.85
        },
        {
          "regex": "metasploit.*(payload|exploit|stager)",
          "confidence": 0.85
        },
        {
          "regex": "powershell.*empire",
          "confidence": 0.85
        },
        {
          "regex": "sliver.*(implant|beacon|session)",
          "confidence": 0.85
        },
        {
          "regex": "Covenant.*(Grunt|Listener)",
          "confidence": 0.85
        },
        {
          "regex": "havoc.*(demon|teamserver)",

YARA rule 'php_webshell_known': Known PHP webshell families (c99, r57, b374k, WSO, etc.) [webshells]

Critical
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched a known webshell pattern (PHP, Python, JSP, or ASPX webshell).

Content

Scanner excerpt · scripts/checks/skillspector_rules.json (reported line 2512)May include surrounding context.

json
dence": 0.8
        },
        {
          "regex": "eval\\s*\\(\\s*gzuncompress\\s*\\(",
          "confidence": 0.8
        },
        {
          "regex": "preg_replace\\s*\\(\\s*['\"]\\/.*\\/e['\"]",
          "confidence": 0.8
        },
        {
          "regex": "create_function\\s*\\(\\s*['\"][^'\"]*['\"]\\s*,\\s*\\$",
          "confidence": 0.8
        },
        {
          "regex": "c99shell",
          "confidence": 0.8
        },
        {
          "regex": "c99_sess_put",
          "confidence": 0.8
        },
        {
          "regex": "r57shell",
          "confidence": 0.8
        },
        {
          "regex": "Web\\ Shell\\ by\\ oRb",
          "confidence": 0.8
        },
        {
          "regex": "WSO\\ ",
          "confidence": 0.8
        },
        {
          "regex": "b374k",
          "confidence": 0.8
        },
        {
          "regex": "STARTER\\ ALFA",
          "confidence": 0.8
        },
        {
          "regex": "weevely",
          "

YARA rule 'crypto_coinjacking': Browser-based cryptojacking scripts (CoinHive, CryptoLoot, etc.) [cryptominers]

Critical
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched cryptocurrency mining indicators (stratum protocol, mining pools, miner binaries, or cryptojacking scripts).

Content

Scanner excerpt · scripts/checks/skillspector_rules.json (reported line 2757)May include surrounding context.

json
85
        },
        {
          "regex": "cryptonight",
          "confidence": 0.85
        },
        {
          "regex": "randomx",
          "confidence": 0.85
        },
        {
          "regex": "coinhive\\.min\\.js",
          "confidence": 0.85
        },
        {
          "regex": "CoinHive\\.Anonymous\\s*\\(",
          "confidence": 0.85
        },
        {
          "regex": "cryptoloot",
          "confidence": 0.85
        },
        {
          "regex": "webmine\\.pro",
          "confidence": 0.85
        },
        {
          "regex": "jsecoin",
          "confidence": 0.85
        },
        {
          "regex": "coin\\-imp",
          "confidence": 0.85
        },
        {
          "regex": "minero\\.cc",
          "confidence": 0.85
        },
        {
          "regex": "monerominer",
          "confidence": 0.85
        },
        {
          "regex": "WebAssembly\\.instantiate.*(mine|hash|crypto)",
          "confidence": 0.85
        }
      ]
    }

Tainted flow: 'req' from os.environ.get (line 762, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cli/cli_reporting.py (reported line 249)May include surrounding context.

python
try:
        req = urllib.request.Request(iam_url, data=body, method="POST",
                                     headers={"Content-Type": "application/json"})
        with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT, context=_ssl_context()) as resp:
            return resp.headers.get("X-Subject-Token")
    except Exception:
        return None

Tainted flow: 'req' from os.environ.get (line 751, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cli/cli_reporting.py (reported line 743)May include surrounding context.

python
if _is_temporary_credential(_ak, _sts):
                    _h["X-Security-Token"] = _sanitize_token(_sts)
                req = urllib.request.Request(ENDPOINT, data=body, method="POST", headers=_h)
                with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT, context=ctx) as resp:
                    if resp.status == 200:
                        return True
            except Exception:

Tainted flow: 'req' from os.environ.get (line 751, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/cli/cli_reporting.py (reported line 754)May include surrounding context.

python
if _is_temporary_credential(_ak, _sts):
                    _h["X-Security-Token"] = _sanitize_token(_sts)
                req = urllib.request.Request(ENDPOINT, data=body, method="POST", headers=_h)
                with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT, context=ctx) as resp:
                    if resp.status == 200:
                        return True
            except Exception:

Tainted flow: 'req' from os.environ.get (line 751, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The guest reporting path sends collected telemetry to GUEST_ENDPOINT whenever it merely starts with 'http', with no allowlist or host validation. Because the module also gathers session identifiers, user input, steps, and token metrics from local agent stores, an attacker who can influence environment variables can redirect sensitive telemetry to an arbitrary external server.

Content

Scanner excerpt · scripts/cli/cli_reporting.py (reported line 765)May include surrounding context.

python
req = urllib.request.Request(
                GUEST_ENDPOINT, data=body, method="POST",
                headers={"Content-Type": "application/json"})
            with urllib.request.urlopen(req, timeout=HTTP_TIMEOUT, context=ctx) as resp:
                return resp.status == 200
        except Exception:
            pass

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Automatic download and installation of executables into ~/.local/bin introduces supply-chain and persistence risk, particularly when not foregrounded as a primary capability. For a skill marketed as an auditor, silently modifying the local environment is more dangerous because operators may run it in sensitive CI or developer contexts.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Exposing --skip-checks gitleaks allows users or upstream automation to disable credential-leak scanning and still use the tool as if it were a security gate. In a security-audit skill, configurable omission of core controls can be abused to mask secrets or weaken enforcement without obvious visibility.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

bash
skill-quality-cli run --skill-name huawei-cloud-skill-audit -- python3 "$AUDIT_DIR/scripts/skill_audit.py" --target .. --checks skillspector
skill-quality-cli run --skill-name huawei-cloud-skill-audit -- python3 "$AUDIT_DIR/scripts/skill_audit.py" --target .. --skip-checks gitleaks

Run with custom tool paths

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Documenting --skip-checks as a normal option normalizes bypassing security controls. In CI or review workflows, this can be exploited to produce incomplete audit results that appear legitimate, undermining the trustworthiness of the gate.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
Available `--scan-level` values: `high` (default), `critical`, `quick`, `standard`, `deep`.
Available `--checks`: `skillspector`, `gitleaks`, `runtime_security`.
Use `--skip-checks` to exclude specific checks.

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Listing --skip-checks in the parameter table makes security bypass part of the supported interface. Because this skill is intended as a compliance/security control, an attacker or careless operator could intentionally omit the strongest scanner and evade detection.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
| `--target` | Yes | Single skill dir or parent folder of skills | `/path/to/skill-dir` |
| `--output-dir` | No | Report output directory (default: parent of target) | `--output-dir ./reports` |
| `--scan-level` | No | Scan depth: high/critical/quick/standard/deep (default: high) | `--scan-level deep` |
| `--checks` | No | Comma-separated checks to run (default: all); valid values are only `skillspector`, `gitleaks`, `runtime_security`. Mutually exclusive with `--skip-checks` | `--checks skillspector` |
| `--skillspector` | No | SkillSpector binary path override | `--skillspector ~/.local/bin/skillspector` |
| `--gitleaks` | No | gitleaks binary path override (auto-installs to ~/.local/bin when missing) | `--gitleaks ~/.local/bin/gitleaks` |
| `--skip-checks` | No | Comma-separated checks to skip; mutually exclusive with `--checks` | `--skip-checks gitleaks` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The same bypass surface is repeated in the options table near --no-install, reinforcing a pattern of user-controlled security reduction. In a gatekeeping tool, this materially weakens assurance and can be leveraged to conceal credential leaks or runtime-dangerous content.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
| `--checks` | No | Comma-separated checks to run (default: all); valid values are only `skillspector`, `gitleaks`, `runtime_security`. Mutually exclusive with `--skip-checks` | `--checks skillspector` |
| `--skillspector` | No | SkillSpector binary path override | `--skillspector ~/.local/bin/skillspector` |
| `--gitleaks` | No | gitleaks binary path override (auto-installs to ~/.local/bin when missing) | `--gitleaks ~/.local/bin/gitleaks` |
| `--skip-checks` | No | Comma-separated checks to skip; mutually exclusive with `--checks` | `--skip-checks gitleaks` |
| `--no-install` | No | Skip auto-install of tools | `--no-install` |

## Report Structure

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
t of all skills found
2. **Issue Summary** — count by severity (CRITICAL/ERROR/WARNING) with rule breakdown (INFO excluded)
3. **Issue Details** — per-issue: skill name, rule, line number, snippet, message
4. **Fix Strategies** — actionable remediation for each unique rule/category

---

## Fix Strategies Reference

### skillspector

| Rule | Fix |
|------|-----|
| P1-P8 (Prompt Injection / System Prompt Leakage) | Do not embed user-controllable input in system prompts; use template variables with explicit escaping |
| E1-E5 (Data Exfiltration) | Remove external URLs; use env vars for API endpoints; restrict network access in tool definitions |
| PE1-PE5 (Privilege Escalation) | Avoid sudo/root commands; use capability-based permissions; do not disable security controls |
| AST (Behavioral AST: AST1-AST7/9/10) | Replace exec()/eval() with safer alternatives; use importlib with allowlists |
| YR1-YR4 (YARA) | Remove reverse shell/webshell patterns; move server functionality to sep

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

md
- `scripts/checks/skillspector_rules.json` — skillspector rules (52 rules / 609 patterns)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/check_registry.py (reported line 34)May include surrounding context.

python
def resolve_enabled_checks(checks_arg: str | None, skip_arg: str | None) -> set[str]:
    """Resolve --checks and --skip-checks into final enabled set."""
    if checks_arg and skip_arg:
        raise ValueError("Cannot use --checks and --skip-checks together")
    if checks_arg:

Static analysis

No suspicious patterns detected.