Back to skill

Security audit

huawei-cloud-sms-host-migrator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Huawei Cloud migration skill, but it gives high-impact infrastructure instructions with unsafe remote installer steps and limited safeguards around credentials and destructive cleanup.

Review and edit the templates before use, especially region, project, VPC, subnet, security group, source server, and target server IDs. Prefer verified installer packages or independently validate downloaded scripts and agent packages before running them, especially with sudo or Administrator rights. Use least-privilege temporary Huawei Cloud credentials where possible, avoid exposing AK/SK in shared terminals or logs, and only run DeleteTask/DeleteTemplate after confirming the migration is complete and the IDs are correct.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code does not perform host migration operations or act as an SMS migration assistant. Its primary function is test automation: parsing test cases, spawning parallel jobs, executing commands, matching outputs, and producing a report. While the script is named for the SMS host migrator and may support validation of such a skill, this code chunk itself does not implement the declared migration workflow capabilities. Therefore the description materially overstates and misrepresents what this code actually does.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

This command fetches a shell script from the internet and pipes execution to bash in the same step, eliminating opportunities for review or integrity checking. In a migration-assistant context, operators may run this on privileged source or target hosts, so compromise of the script source could lead to full host takeover, credential theft, or persistence across migration workflows.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 11)May include surrounding context.

Download and execute the installer script for your target site:

bash
# China Site (cn-north-4):
curl -sSL "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh" -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

# International Site (Singapore ap-southeast-3):
curl -sSL "https://ap-southeast-3-hwcloudcli.obs.ap-southeast-3.myhuaweicloud.com/cli/latest/hcloud_install.sh" -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

This second regional installer uses the same unsafe pattern of downloading and executing a remote shell script without verification. The skill's operational scope increases risk because users performing server migration often have elevated permissions and access to sensitive infrastructure, magnifying the impact of any supply-chain or hosting compromise.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 14)May include surrounding context.

curl -sSL "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh" -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

International Site (Singapore ap-southeast-3):

curl -sSL "https://ap-southeast-3-hwcloudcli.obs.ap-southeast-3.myhuaweicloud.com/cli/latest/hcloud_install.sh" -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Windows (PowerShell)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes reading local reference and template files (references/..., templates/...) but does not declare any explicit tool scope such as permissions or allowed-tools. Missing scope boundaries can let an agent invoke file-read behavior without a clear least-privilege contract, increasing the chance of unintended access if the runtime grants broader filesystem visibility.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

Due to a KooCLI JSON serialization defect (tested on v7.2.12), backslashes in Windows partition paths and UUIDs must be double-escaped in --cli-jsonInput files (use 4 backslashes, e.g., "name": "C:\\\\"). Use templates/create-task-windows.json (BIOS) or templates/create-task-existing-server.json (UEFI). Note: If a future KooCLI update fixes this serialization defect, revert to standard JSON escaping ("name": "C:\\"). Verify outbound payload using --dryrun when updating KooCLI. See references/troubleshooting-guide.md.

bash
# Create task for Linux source host (template auto-provisioning):
hcloud SMS CreateTask --cli-region=cn-north-4 --cli-jsonInput="templates/create-task.json"

# Create task for BIOS Windows source host (template auto-provisioning):

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

Due to a KooCLI JSON serialization defect (tested on v7.2.12), backslashes in Windows partition paths and UUIDs must be double-escaped in --cli-jsonInput files (use 4 backslashes, e.g., "name": "C:\\\\"). Use templates/create-task-windows.json (BIOS) or templates/create-task-existing-server.json (UEFI). Note: If a future KooCLI update fixes this serialization defect, revert to standard JSON escaping ("name": "C:\\"). Verify outbound payload using --dryrun when updating KooCLI. See references/troubleshooting-guide.md.

bash
# Create task for Linux source host (template auto-provisioning):
hcloud SMS CreateTask --cli-region=cn-north-4 --cli-jsonInput="templates/create-task.json"

# Create task for BIOS Windows source host (template auto-provisioning):

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

Due to a KooCLI JSON serialization defect (tested on v7.2.12), backslashes in Windows partition paths and UUIDs must be double-escaped in --cli-jsonInput files (use 4 backslashes, e.g., "name": "C:\\\\"). Use templates/create-task-windows.json (BIOS) or templates/create-task-existing-server.json (UEFI). Note: If a future KooCLI update fixes this serialization defect, revert to standard JSON escaping ("name": "C:\\"). Verify outbound payload using --dryrun when updating KooCLI. See references/troubleshooting-guide.md.

bash
# Create task for Linux source host (template auto-provisioning):
hcloud SMS CreateTask --cli-region=cn-north-4 --cli-jsonInput="templates/create-task.json"

# Create task for BIOS Windows source host (template auto-provisioning):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L105 states that all documentation and configuration files must be written strictly in English, which is a natural-language locale policy constraint. The file does not provide user choice, opt-in, or a clear justified compliance reason for enforcing a single language.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 47)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 47)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting-guide.md (reported line 70)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Step 3: Enter Authentication Out-of-Band

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 48)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Step 3: Enter Authentication Out-of-Band

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 117)May include surrounding context.

Step 2: Run the Startup Script

bash
# Execute with root privileges (or via nohup for background execution)
sudo ./startup.sh

Step 3: Enter Authentication Out-of-Band

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs operators to enter Huawei Cloud AK/SK credentials during agent installation but provides no safeguards about secret handling, least-privilege IAM use, terminal history, screen sharing, logging exposure, or immediate credential rotation if exposed. In a migration workflow, these credentials may grant broad cloud control, so omission of safe-handling guidance materially increases the chance of credential leakage and subsequent account compromise.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 120)May include surrounding context.

md
sudo ./check_agent.sh

# Restart agent process
sudo ./stop.sh
sudo ./startup.sh

# Inspect runtime logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/agent-deployment-guide.md (reported line 121)May include surrounding context.

md
sudo ./check_agent.sh

# Restart agent process
sudo ./stop.sh
sudo ./startup.sh

# Inspect runtime logs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Linux installation instructions direct users to download and immediately execute a remote shell script, but do not include any integrity verification, signature validation, or review step. If the hosting endpoint, CDN path, or transport chain were compromised, users could execute attacker-controlled code on their systems during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documents DeleteTask and DeleteTemplate commands that permanently remove migration resources, but it does not include an explicit warning, confirmation guidance, or rollback/cross-check steps near those commands. In an operational migration skill, this can lead users or downstream agents to execute destructive cleanup prematurely, causing loss of migration state, broken workflows, or accidental deletion of active resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide instructs users to run hcloud SMS DeleteTask to release bindings and later DeleteTemplate, which are destructive operations affecting migration state and associated resources. The surrounding text explains the purpose, but it does not explicitly warn that deletion may be irreversible or should be confirmed before execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

bash
     hcloud SMS DeleteTemplate --cli-region={region} --id="{template_id}"
     ```
  3. If `DeleteTemplate` returns error `SMS.7101`, the template has already been automatically deleted; treat this as a successful completion.

### KooCLI Multi-Version Preamble Warning Breaking JSON Parsing (`VPC ListVpcs`)
- **Symptom**: Running `hcloud VPC ListVpcs` outputs a localized disclaimer line before the JSON object, causing `json.loads()` or programmatic JSON parsers to fail with syntax errors.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/troubleshooting-guide.md (reported line 88)May include surrounding context.

bash
     hcloud SMS DeleteTemplate --cli-region={region} --id="{template_id}"
     ```
  3. If `DeleteTemplate` returns error `SMS.7101`, the template has already been automatically deleted; treat this as a successful completion.

### KooCLI Multi-Version Preamble Warning Breaking JSON Parsing (`VPC ListVpcs`)
- **Symptom**: Running `hcloud VPC ListVpcs` outputs a localized disclaimer line before the JSON object, causing `json.loads()` or programmatic JSON parsers to fail with syntax errors.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hard-codes region_id, region_name, and project context to cn-north-4, which can cause migrations to be created in an unintended geographic or compliance boundary without explicit user selection. In a host migration skill, this is more sensitive because it may direct replicated system data and resulting compute resources into the wrong jurisdiction, project, or network environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-like JSON sets the deployment region to "cn-north-4", which imposes a specific locale/region choice in natural-language/config semantics. Under the policy, forcing a specific language or locale without opt-in or clear justification is a reportable issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guide tells users to extract files and update the user PATH environment variable, which changes the local system configuration. Although the command is shown, there is no explicit user-facing warning that the step persists configuration changes to the user's environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.