Back to skill

Security audit

huawei-cloud-smn-dms-message

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its Huawei Cloud messaging purpose, but it installs/reporting tooling and can run costly or destructive cloud actions without an enforced approval gate.

Install only if you are comfortable with a skill that manages real Huawei Cloud messaging resources, installs a reporting CLI under your user account, and sends execution-quality metadata. Use least-privilege Huawei credentials, verify KooCLI and skill-quality-cli provenance, set the actual opt-out variable SKILL_QUALITY_DISABLE=1 if reporting is not acceptable, and do not allow R2/R1 actions unless the exact command has been previewed and explicitly approved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smn_dms_skill.py:33
Finding

State-Changing Cloud Operations Lack an Enforced Confirmation Gate

Content
View full analysis

Vulnerability Details

File Location: scripts/smn_dms_skill.py:33-45, 234-259, 291-292
Vulnerability Type: Confirmation bypass for destructive and billable operations
Risk Level: High

Complete Code Snippet

python
def run_hcloud(args_list, region, preview=False):
    cmd = ["hcloud"] + args_list
    if region:
        cmd.append("--cli-region=%s" % region)
    if preview:
        print("[PREVIEW] " + " ".join(cmd))
        return ""
    try:
        proc = subprocess.run(cmd, capture_output=True, text=True, timeout=60)
python
def delete_smn_topic(a):
    require(a.topic_urn, "topic_urn", sys.argv)
    print_json(run_hcloud(["SMN", "DeleteTopic", "--topic_urn=%s" % a.topic_urn],
                          a.region, preview=a.preview))


def confirm_smn_subscription(a):
    require(a.token, "token", sys.argv)
    args = ["SMN", "ConfirmSubscription", "--token=%s" % a.token]
    if a.topic_urn:
        args.append("--topic_urn=%s" % a.topic_urn)
    if a.endpoint:
        args.append("--endpoint=%s" % a.endpoint)
    print_json(run_hcloud(args, a.region, preview=a.preview))


def delete_dms_instance(a):
    engine = (a.engine or "").lower()
    require(engine, "engine (kafka|rabbitmq|rocketmq)", sys.argv)
    validate_engine(engine, sys.argv)
    service = ENGINE_SERVICE[engine]
    require(a.instance_id, "instance_id", sys.argv)
    print_json(run_hcloud([service, "DeleteInstance",
                           "--instance_id=%s" % a.instance_id], a.region, preview=a.preview))
python
p.add_argument("--preview", action="store_true",
               help="print the hcloud command without executing it (R2/R1 confirmation)")

Technical Analysis

The Skill documentation classifies resource creation and message publication as R2 operations requiring preview and user confirmation, while deletion and subscription confirmation are R1 operations requiring explicit end-to-end approval. The executable entry point does not enforce th ...[truncated 2785 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make preview-only behavior the default for every R1 and R2 action. Do not interpret omission of --preview as authorization to execute.
  2. Separate preview and execution explicitly, such as with an --execute flag that is rejected unless accompanied by valid confirmation proof.
  3. Generate a short-lived confirmation token from the normalized action name, service, region, resource identifiers, and all operation parameters shown in the preview.
  4. Require the execution request to present that token and verify that the parameters exactly match the previewed command. Reject changed, missing, expired, or replayed confirmations.
  5. For R1 operations, require an additional explicit destructive-action acknowledgement bound to the resource identifier and documented impact.
  6. Consider an interactive confirmation prompt for direct human CLI use, while retaining a cryptographically bound approval mechanism for Agent or automated use.
  7. Keep R3 read-only actions outside this gate, but maintain a strict allowlist so newly added state-changing operations cannot be misclassified as read-only.
  8. Add automated tests proving that every R1 and R2 action fails closed when invoked without valid approval, while --preview never executes hcloud.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This second mismatch is substantively the same issue: the documented purpose centers on cloud resource management, while the actual workflow includes downloading, verifying, extracting, and installing binaries locally. Hidden operational breadth increases the chance of users authorizing the skill without understanding that it changes the local execution environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This second mismatch is substantively the same issue: the documented purpose centers on cloud resource management, while the actual workflow includes downloading, verifying, extracting, and installing binaries locally. Hidden operational breadth increases the chance of users authorizing the skill without understanding that it changes the local execution environment.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
93% confidence
Finding

The skill embeds a hidden/secondary operational requirement that every action must first ensure a telemetry CLI is installed and available. Hidden mandatory bootstrap steps are dangerous because they can smuggle in unreviewed execution paths, alter trust boundaries, and cause networked installation behavior before the user-requested cloud task occurs.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
# Huawei Cloud SMN / DMS Messaging Skill

<!-- cli-install-version: 3.9.0 -->
## Step 0: Ensure skill-quality-cli (required; installed on first use)

**Mandatory**: before running any `huawei_*` action, ensure `skill-quality-cli` is installed

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill tells the runtime to download and immediately execute a remote installation script via curl-and-bash. Even if the source is a vendor bucket, this pattern is a classic supply-chain risk: compromise of the hosting location, DNS/TLS path, or script content would yield arbitrary code execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

Install and configure the Huawei Cloud KooCLI:

bash
curl -O https://cn-north-4-hcli.obs.cn-north-4.myhuaweicloud.com/hcli_install.sh && bash hcli_install.sh
# verify: hcloud --help should print the KooCLI version banner

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This is a direct remote-script execution pattern: a script is fetched from an external URL and immediately run with bash. Even though the URL is an official-looking Huawei Cloud endpoint and the overall document is a CLI install guide, the pattern still creates a significant supply-chain risk because compromise of the endpoint or script contents would lead to arbitrary command execution on the user's machine.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 10)May include surrounding context.

bash
# Chinese mainland default mirror
curl -O https://cn-north-4-hcli.obs.cn-north-4.myhuaweicloud.com/hcli_install.sh && bash hcli_install.sh

# Verify
hcloud -v

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell commands, reads environment-based credentials, and instructs installation/execution of local CLIs, yet it declares no explicit tool scope such as allowed-tools or permissions. That gap weakens containment and makes it easier for an agent runtime to grant broader shell/env access than users expect.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: huawei-cloud-smn-dms-message
description: |
  Manage Huawei Cloud SMN (Simple Message Notification) topics, subscriptions, message templates and message publishing, and manage DMS (Distributed Message Service) Kafka/RabbitMQ/RocketMQ instances and Kafka topics. 15 built-in actions cover query (list topics/subscriptions/message templates/DMS instances/Kafka topics), diagnosis (subscription confirmation status, DMS instance health & capacity), management (create topic, add subscription, create message template, publish message, create DMS instance) and destructive operations (delete SMN topic, confirm subscription, delete DMS instance). KooCLI has no DMS command; the three engine services are the only DMS entry points. Supports both AK/SK and local KooCLI profile authentication.
  Use this skill when the user wants to: (1) list or create SMN topics and subscriptions, (2) send or diagnose notifications, (3) inspect SMN subscription confirmation status, (4) list, create, or delete DMS Kafka/RabbitMQ/RocketMQ instances, (5) list Kafka topics, (6) analyze DMS instance health or capacity.
  Triggers include: "SMN", "SMN主题", "消息通知", "subscribe", "topic", "发布消息", "推送消息", "notification", "DMS", "Kafka", "RabbitMQ", "RocketMQ", "消息队列", "DMS实例", "Kafka实例", "RabbitMQ实例", "RocketMQ实例", "订阅", "消息模板", "MQS"
tags: ["smn", "dms", "kafka", "rabbitmq", "rocketmq"]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger set includes broad generic terms like "topic," "notification," and "subscribe," which can cause the skill to activate in unrelated contexts. For a skill that can install software and manage cloud resources, accidental invocation materially raises risk of unintended command generation or execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| Family | Actions | Execution | Risk |
|--------|---------|-----------|------|
| **R3 — Query / Diagnose** (7) | `huawei_list_smn_topics`, `huawei_list_smn_subscriptions`, `huawei_list_smn_message_templates`, `huawei_list_dms_instances`, `huawei_list_dms_topics`, `huawei_analyze_smn_subscription_confirmation`, `huawei_analyze_dms_instance_status` | **Auto-execute** (read-only) | No |
| **R2 — Manage** (5) | `huawei_create_smn_topic`, `huawei_add_smn_subscription`, `huawei_create_smn_message_template`, `huawei_publish_smn_message`, `huawei_create_dms_instance` | **Preview command + ask user to confirm** before running | Yes (creates resources / spends money) |
| **R1 — Destructive** (3) | `huawei_delete_smn_topic`, `huawei_confirm_smn_subscription`, `huawei_delete_dms_instance` | **End-to-end confirmation**: present full command + describe irreversible impact, require explicit user approval | High (deletes/changes state, SMS/email side effects) |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

unified script/agent (wrapper) executor entry point:

bash
# R3 — Query / Diagnose (read-only, auto-execute)
python3 scripts/smn_dms_skill.py huawei_list_smn_topics --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_subscriptions --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_message_templates --region={region}

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

unified script/agent (wrapper) executor entry point:

bash
# R3 — Query / Diagnose (read-only, auto-execute)
python3 scripts/smn_dms_skill.py huawei_list_smn_topics --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_subscriptions --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_message_templates --region={region}

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

unified script/agent (wrapper) executor entry point:

bash
# R3 — Query / Diagnose (read-only, auto-execute)
python3 scripts/smn_dms_skill.py huawei_list_smn_topics --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_subscriptions --region={region}
python3 scripts/smn_dms_skill.py huawei_list_smn_message_templates --region={region}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs users to download and immediately execute a remote shell script with curl ... && bash, but provides no integrity verification, signature check, pinning, or explicit warning about the trust boundary. If the hosting location, network path, or referenced script is compromised, users could execute arbitrary code on their local system during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes DMS management flows including DeleteInstance operations for multiple engines, but it provides no warning that these actions are destructive or may remove user-managed infrastructure. For markdown files, safety-affecting behaviors that impact user data or system integrity should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

Sub[Subscription confirmation analysis] --> LSub[engine SMN ListSubscriptions] LSub --> s0{status == 0?} s0 -->|yes| need[Needs confirmation: ping-back / email click] s0 -->|no| doneok[Confirmed / no confirmation required]

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 59)May include surrounding context.

Sub[Subscription confirmation analysis] --> LSub[engine SMN ListSubscriptions] LSub --> s0{status == 0?} s0 -->|yes| need[Needs confirmation: ping-back / email click] s0 -->|no| doneok[Confirmed / no confirmation required]

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/engine-operation-reference.md (reported line 27)May include surrounding context.

md
|--------|---------|---------------|
| 0 | Not confirmed | HTTP/HTTPS endpoint ping-back or email click-link |
| 1 | Confirmed | None |
| 2 | No confirmation required | None |
| 3 | Cancelled | Re-add if still needed |
| 4 | Deleted | Re-add if still needed |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/verification-method.md (reported line 51)May include surrounding context.

md
## 5. Full behavioral test (optional, requires real resources + confirmation)

1. Create a topic (`huawei_create_smn_topic`) → confirm it appears in `huawei_list_smn_topics`.
2. Add an email subscription (`huawei_add_smn_subscription`) → confirm `status=0` until the user
   clicks the mail link, then `status=1`.
3. Publish a message (`huawei_publish_smn_message`) → recipient receives it (email/SMS billing applies).

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/ensure_cli.sh (reported line 103)May include surrounding context.

sh
ensure_version_meta() {
    local vf="$HOME/.skill-quality/version.json"
    [ -f "$vf" ] && return 0
    mkdir -p "$HOME/.skill-quality"
    printf '{"version": "%s", "installed_at": %s, "path": "%s"}\n' \
        "$PINNED_VERSION" "$(date +%s)" "${INSTALL_DIR}/skill-quality-cli" > "$vf"
}

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 87)May include surrounding context.

sh
tar xzf "${TMPDIR}/sqc.tar.gz" -C "${TMPDIR}" --no-same-owner

mkdir -p ~/.local/bin/skill-quality-cli.d
cp "${TMPDIR}/skill-quality-cli" ~/.local/bin/ || true
cp "${TMPDIR}/skill-quality-cli.bin" ~/.local/bin/ || true
cp "${TMPDIR}/skill-quality-cli.d/cli_entry.py" ~/.local/bin/skill-quality-cli.d/ || true

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The code makes an autonomous decision to report execution details externally on every run, independent of the user's requested SMN/DMS action. In a security-sensitive cloud administration skill, unrequested autonomous behavior is risky because it performs extra network-relevant actions outside the declared operational objective and outside explicit user approval.

Content

Scanner excerpt · scripts/smn_dms_skill.py (reported line 8)May include surrounding context.

python
SMN maps to `hcloud SMN`; DMS has no `hcloud DMS` service, so the engine
(Kafka / RabbitMQ / RocketMQ) selects the actual KooCLI service.

Every run automatically sends a quality report via `skill-quality-cli` (installed by
`scripts/ensure_cli.sh`, pinned version with SHA256 verification) — fire-and-forget,
non-blocking, never changes the business output or exit code. When the whole
command is already wrapped with `skill-quality-cli run` (SKILL_TRACE_ID is set),

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description presents SMN/DMS management functions, but the implementation also performs automatic quality reporting on every execution. This mismatch is dangerous because users and calling agents may not realize operational metadata is exfiltrated to another tool/service, undermining informed consent and violating least surprise for an infrastructure-management skill.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/smn_dms_skill.py (reported line 45)May include surrounding context.

python
print("[PREVIEW] " + " ".join(cmd))
        return ""
    try:
        proc = subprocess.run(cmd, capture_output=True, text=True, timeout=60)
    except subprocess.TimeoutExpired:
        raise RuntimeError("hcloud 命令超时")
    if proc.returncode != 0:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The quality-reporting subprocess is unrelated to the declared cloud resource management purpose and introduces a second external execution path. In a skill that manages cloud messaging and queue infrastructure, such hidden side behavior expands the trust boundary and can leak execution details or enable abuse if the reporting binary is replaced or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automatic external reporting sends status, error code/message, skill name, and timing metadata without a user-facing warning at the point of operation. In a cloud operations context, even metadata can reveal sensitive usage patterns, failure states, or internal identifiers, especially when error messages may contain service details returned by hcloud.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.