Back to skill

Security audit

huawei-cloud-storage-query

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only Huawei Cloud storage query tool, but its setup and API clients disable TLS verification and can install or execute network code while cloud credentials are present.

Review before installing. Use only least-privilege read-only Huawei Cloud credentials, preferably in an isolated environment, and avoid running setup while sensitive credentials are present. The package should enable TLS verification, remove unauthenticated get-pip execution, pin and hash dependencies, and avoid --trusted-host package installs before it is suitable for routine use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/ensure_env.py:278
Finding

Unauthenticated Remote Python Payload Download and Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py, lines 28 and 278–291
Vulnerability Type: Remote payload retrieval and execution without TLS authentication
Risk Level: High

Vulnerable Code

python
ssl._create_default_https_context = ssl._create_unverified_context
python
get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py")
urls = [
    "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py",
    "https://bootstrap.pypa.io/get-pip.py",
]

ctx = ssl._create_unverified_context()

for url in urls:
    info(f"Attempting to download get-pip.py: {url}")
    try:
        urllib.request.urlretrieve(url, get_pip_path, context=ctx)
    except Exception as e:
        print(f"Download failed: {e}")
        continue

    rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)

Technical Analysis

The mandatory environment bootstrap falls back to downloading get-pip.py when neither pip nor ensurepip is available. It explicitly creates an unverified TLS context and globally replaces Python's default HTTPS context with an unverified context.

The downloaded file is not authenticated through a valid server certificate, cryptographic digest, or digital signature. It is then immediately executed by the current Python interpreter. Consequently, the HTTPS URL does not establish an authenticated code origin.

This path is reachable when:

  1. The Skill's required environment check is invoked.
  2. pip is unavailable.
  3. ensurepip --upgrade fails.
  4. One of the configured download URLs is reachable through an attacker-controlled or intercepted network path.

Attack Path

  1. The user or Agent invokes the environment check required by SKILL.md.
  2. _ensure_pip() determines that pip is unavailable and that ensurepip cannot install it.
  3. A network attacker intercepts the request to a configured get-pip.py endpoint.
  4. Because certificate verification is disabled, the attacker supplies an a ...[truncated 1006 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the global override:
    python
    ssl._create_default_https_context = ssl._create_unverified_context
    
  2. Do not use ssl._create_unverified_context() for executable downloads. Use the default verified TLS context.
  3. Prefer failing safely and instructing the user to install pip through a trusted operating-system package manager.
  4. If downloading a bootstrap script remains necessary:
    • Use a canonical authenticated source.
    • Pin an expected SHA-256 digest distributed independently of the downloaded file.
    • Verify the digest before execution.
    • Prefer a signed artifact and validate its signature against a pinned public key.
  5. Create temporary files securely and remove the downloaded script after successful or failed verification.
  6. Abort execution on any certificate, hostname, digest, or signature validation failure.

T08 · Insecure Dependencies

Error
Location
scripts/ensure_env.py:307
Finding

Dependency Installation Through TLS-Unverified Package Mirrors

Content
View full analysis

Vulnerability Details

File Location: scripts/ensure_env.py, lines 307–366
Vulnerability Type: Insecure dependency installation from unauthenticated package sources
Risk Level: High

Vulnerable Code

python
def _find_fastest_mirror():
    """Lightweight probe for an available mirror, returning the first reachable URL."""
    mirrors = [
        "https://repo.huaweicloud.com/repository/pypi/simple",
        "https://pypi.tuna.tsinghua.edu.cn/simple",
        "https://mirrors.aliyun.com/pypi/simple",
    ]
    for url in mirrors:
        try:
            req = urllib.request.Request(url, method="HEAD")
            resp = urllib.request.urlopen(req, timeout=5)
            if resp.status == 200:
                print(f" Available mirror: {url}")
                return url
        except Exception:
            continue
    print(" No available mirror; attempting the official source")
    return None
python
mirror_url = _find_fastest_mirror()
pip_timeout = "30"

pip_cmd = [sys.executable, "-m", "pip", "install", "-r", req_file]

if UPGRADE:
    pip_cmd.append("--upgrade")

if mirror_url:
    host = mirror_url.split("//")[1].split("/")[0]
    rc, out, err = run_cmd(
        pip_cmd + ["-i", mirror_url, "--trusted-host", host,
                   "--timeout", pip_timeout, "--retries", "2"],
        timeout=120,
    )
    if rc == 0:
        print(" Dependency installation succeeded")
        return True

The installed requirements are also specified only by lower bounds:

text
huaweicloudsdkcore>=3.1.0
huaweicloudsdkiam>=3.1.0
huaweicloudsdkevs>=3.1.0
huaweicloudsdksfsturbo>=3.1.0
huaweicloudsdkobs>=3.1.0
huaweicloudsdkcbr>=3.1.0

Technical Analysis

When dependencies are missing, the mandatory setup selects the first reachable mirror and invokes pip with --trusted-host. For the selected host, this option permits installation without normal HTTPS certificate and hostname authentication.

The dependency fil ...[truncated 1716 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove --trusted-host and require valid TLS certificate and hostname verification for all indexes and artifact downloads.
  2. Avoid automatic mirror selection for security-sensitive installation. Use one explicitly configured, authenticated package index.
  3. Pin exact dependency versions instead of unrestricted lower bounds.
  4. Generate a reviewed lock file containing cryptographic hashes and install with:
    bash
    pip install --require-hashes -r requirements.txt
    
  5. Perform dependency installation before requesting or loading cloud credentials where practical.
  6. Separate environment preparation from credential validation so package installation does not inherit HW_ACCESS_KEY, HW_SECRET_KEY, or HW_SECURITY_TOKEN.
  7. Fail closed if TLS or package-integrity verification fails.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:43
Finding

TLS Certificate Verification Disabled for Authenticated Cloud API Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py, lines 7–8 and 43–44
Vulnerability Type: Improper certificate validation for authenticated API traffic
Risk Level: Medium

Vulnerable Code

python
# Suppress warnings caused by ignore_ssl_verification
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
python
def build_http_config():
    """Build HTTP configuration with environment-variable proxy support."""
    http_config = HttpConfig.get_default_config()
    http_config.ignore_ssl_verification = True
    http_config.timeout = (30, 60)
    http_config.retry_times = 3

    proxy_url = _get_proxy_url()
    if proxy_url:
        parsed = urlparse(proxy_url)
        http_config.proxy_protocol = parsed.scheme or "http"
        http_config.proxy_host = parsed.hostname or ""
        http_config.proxy_port = parsed.port or 8080
        http_config.proxy_user = parsed.username or ""
        http_config.proxy_password = parsed.password or ""

    return http_config

Technical Analysis

build_http_config() is shared by the environment credential check and the service-query scripts. It unconditionally sets ignore_ssl_verification to True, disabling certificate-chain and hostname validation for Huawei Cloud SDK connections. The corresponding warning is globally suppressed, reducing visibility of the insecure connection.

These clients authenticate requests using HW_ACCESS_KEY, HW_SECRET_KEY, and, where applicable, HW_SECURITY_TOKEN. Without server authentication, a network intermediary can impersonate the expected API endpoint. Although request signing may prevent straightforward modification of some signed fields, it does not restore server identity verification or protect sensitive response data from a successful TLS interception. Temporary security tokens included in authenticated requests may also be exposed to the intermediary.

The optional use of environment-configured HTTP or HTTPS proxies make ...[truncated 1518 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the insecure assignment or explicitly enable verification:
    python
    http_config.ignore_ssl_verification = False
    
  2. Remove the global suppression of InsecureRequestWarning.
  3. Use the operating system's trusted CA store by default.
  4. For private enterprise proxies or endpoints, support an explicitly configured CA bundle rather than disabling verification.
  5. Validate proxy configuration and document that proxy administrators can observe connection metadata.
  6. Add automated tests confirming that invalid, expired, self-signed, and hostname-mismatched certificates are rejected.
  7. Treat TLS validation failures as fatal and do not silently retry over an unauthenticated channel.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to query storage services, but it also performs IAM project and region-to-project lookup operations that are not clearly disclosed in the storage-focused description. Even if read-only, undisclosed IAM access expands the data exposure scope and can reveal account structure or metadata that users did not intend to share when invoking a storage query tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims to query storage services, but it also performs IAM project and region-to-project lookup operations that are not clearly disclosed in the storage-focused description. Even if read-only, undisclosed IAM access expands the data exposure scope and can reveal account structure or metadata that users did not intend to share when invoking a storage query tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to query storage services, but it also performs IAM project and region-to-project lookup operations that are not clearly disclosed in the storage-focused description. Even if read-only, undisclosed IAM access expands the data exposure scope and can reveal account structure or metadata that users did not intend to share when invoking a storage query tool.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/check_env.ps1 (reported line 1)May include surrounding context.

text
<#
华为云资源查询 - 环境检查前置脚本 (Windows PowerShell)
#>

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 69)May include surrounding context.

python
# 用 venv Python 重新执行当前脚本
    print(f"  使用虚拟环境 Python: {venv_python}")
    os.execv(venv_python, [venv_python] + sys.argv)

def info(msg):
    print(f"  {msg}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script downloads packages from the network and may fetch and execute get-pip.py, while SSL certificate verification has been globally disabled. This creates a serious supply-chain risk: a man-in-the-middle or compromised mirror could deliver malicious code that would then be executed locally during environment setup.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to execute shell commands, access environment variables, and make networked SDK/API calls, but it does not declare any explicit tool scope such as allowed-tools or permissions. That omission weakens policy enforcement and reviewability, making it easier for a supposedly read-only skill to perform broader local and network actions than a consumer might expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This script enumerates domain-level projects via CBR using a required domain_name parameter, which goes beyond the manifest’s stated scope of querying storage resources such as volumes, buckets, file systems, and backups. Even though it is read-only, exposing tenant/project enumeration can leak organizational structure and identifiers that enable reconnaissance, broaden account mapping, and support follow-on abuse in a multi-project cloud environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes read-only querying of CBR storage resources such as vaults, policies, backups, tasks, agents, and protectables. This file instead calls list_projects, which enumerates IAM/account project metadata rather than backup/storage resources, extending behavior beyond the stated EVS/OBS/SFS/CBR storage-query scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script loads access credentials at L13 and then uses them to call the Huawei Cloud CBR API at L35. While the file prints errors and results, it does not disclose to the user that credentials will be accessed and that checkpoint metadata will be transmitted to an external cloud service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This script exposes CBR tenant/domain metadata via show_domain, which is broader than the skill manifest’s declared read-only CBR scope of vaults, backups, policies, tasks, agents, and protectables. Even though it is a read operation, project/domain identifiers and names are sensitive cloud-environment metadata that can aid reconnaissance, cross-project enumeration, or unintended disclosure when users expect only storage-resource queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code fetches and prints detailed CBR vault information including project_id, user_id, resource identifiers, tags, and backup-related metadata. There is no confirmation prompt, cautionary message, or inline warning that the command will display potentially sensitive infrastructure and account data to stdout.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This PowerShell script presents its title, status messages, and failure guidance entirely in Chinese, which enforces a specific language for users. The policy allows locale constraints only when they are explicitly justified or when users are given a choice, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's user-facing comments and output messages are entirely in Chinese, including failure and remediation guidance. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 39)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/check_env.sh (reported line 40)May include surrounding context.

sh
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 186)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 187)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 188)May include surrounding context.

python
echo ""
    echo "请先安装 Python 3.6+,根据当前系统参考:"
    echo "  macOS   : brew install python"
    echo "  Ubuntu  : sudo apt update && sudo apt install -y python3 python3-pip"
    echo "  CentOS  : sudo yum install -y python3"
    exit 1
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code explicitly disables TLS certificate verification with ignore_ssl_verification = True and also suppresses the resulting warning globally via urllib3.disable_warnings(...). In a cloud-storage query skill that handles Huawei Cloud credentials and may traverse a proxy, this enables man-in-the-middle interception or response tampering, potentially exposing AK/SK or allowing falsified cloud data to be returned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing description and console output are entirely in Chinese, which effectively imposes a specific language on all users. There is no opt-in, alternate locale, or explanation that this skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The advertised scope is storage-resource querying, but the script validates credentials by listing IAM users and includes project/ECS-oriented checks in comments and helper functions. This broader API access increases the blast radius of supplied credentials and violates least privilege relative to the stated skill purpose.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

The command wrapper defaults to timeout=None, which can allow child processes to hang indefinitely if callers omit a timeout. In an environment-setup script that launches package managers and bootstrap tools, this can lead to denial-of-service behavior or stalled automation pipelines.

Content

Scanner excerpt · scripts/ensure_env.py (reported line 129)May include surrounding context.

python
# ── 工具函数 ──────────────────────────────────────────────────────────

def run_cmd(cmd, timeout=None, **kwargs):
    """运行命令,返回 (returncode, stdout, stderr)

    Args:

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/ensure_env.py:284