Back to skill

Security audit

huawei-cloud-swr-image-governance

Security checks for vulnerabilities and agentic risk

Overview

This cloud governance skill is coherent, but it deserves Review because it combines broad SWR write/delegation authority with unsafe CLI installation guidance that runs unverified downloaded code.

Install only if you are comfortable giving an agent guided access to Huawei Cloud SWR governance actions. Use least-privilege, preferably temporary credentials; avoid the non-interactive installer; verify any downloaded hcloud installer before running it; and require a human to review exact commands before retention, permission, shared-domain, or agency changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The command downloads a shell script from the network and immediately executes it with bash, creating a classic remote-code-execution and supply-chain risk if the hosting location, transport, or artifact is compromised. In the context of a cloud administration skill, users may run this on systems that also hold cloud credentials, amplifying the potential damage.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This variant is more dangerous because it both executes a remotely fetched script and suppresses confirmation with '-y', making unattended compromise easier. If the script or distribution endpoint were tampered with, the command could perform arbitrary local actions and potentially capture or misuse Huawei Cloud credentials present in the environment.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
| Grant repo permission | `CreateUserRepositoryAuth` | 🟡 Medium | Grants access to specific repository. **If auth=7, grants full control of this repository** |
| Update repo permission | `UpdateUserRepositoryAuth` | 🟡 Medium | Changes access level for repository. **Permission downgrade may break existing workflows that depend on the current access level** |
| Revoke repo permission | `DeleteUserRepositoryAuth` | 🟠 High | Removes all access to repository. **May cause business interruption — services pulling from this repo will immediately lose access** |
| Create retention rule | `CreateRetention` | 🟠 High | Creates automated cleanup policy. **When the rule executes, tags not matching retention conditions are automatically deleted and data is unrecoverable** |
| Update retention rule | `UpdateRetention` | 🟠 High | Modifies cleanup policy. **Changing conditions may cause previously retained tags to be deleted — data is unrecoverable** |
| Delete retention rule | `DeleteRetention` | 🟡 Medium | Removes automated cleanup policy. Existing tags are preserved, but no future cleanup will occur |
| Create shared domain | `CreateRepoDomains` | 🟡 Medium | Shares images with another account via cross-organization access |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes a write operation that creates an SWR agency delegation, explicitly granting SWR access to other services such as OBS and CCE on the user's behalf. Even though the documentation warns about confirmation, this materially expands privilege scope beyond repository governance and can enable cross-service actions if invoked with overly broad cloud permissions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 131)May include surrounding context.

Do you want to proceed? (yes/no)

text

**Error:** Execute write operations without confirmation
```bash
# Directly executing Create/Update/Delete without user confirmation is prohibited
hcloud SWR DeleteNamespaceAuth --namespace=pancake --1=<user-id> --cli-region=cn-north-4

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs users to download and execute an installation script and to perform privileged system modifications, but it does not prominently warn that these actions will change the local system and should only be done after verifying the source and reviewing the script. In a security-sensitive skill for cloud governance tooling, normalizing direct execution of downloaded code increases the chance of supply-chain compromise or unsafe execution by less experienced users.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The non-interactive '-y' installation path removes the confirmation prompt and encourages unattended execution of a downloaded installer. When combined with remote script execution, this reduces user review and increases the likelihood of unintended or unsafe system changes proceeding automatically.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

Download and run official installation script (interactive)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 49)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 54)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 76)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The credential setup section tells users to export long-lived or temporary cloud credentials into the shell session but does not clearly warn that these secrets may remain accessible in the session environment, shell history, child processes, logs, or shared systems. Because these are cloud access credentials for SWR governance operations, accidental exposure could enable unauthorized registry and IAM actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes concrete permission-granting examples that can lead operators to copy-paste access-changing commands without an explicit warning about least-privilege, scope, or required authorization. In this skill context, those examples are operationally relevant, but SWR namespace and repository permissions directly affect access to container images and can unintentionally overgrant or alter trust boundaries if used carelessly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide documents CreateAgency with only a brief use-case note, but this action creates a delegation that allows SWR to access other services on the user's behalf. Without a prominent warning and scope explanation, users may grant broad cross-service access they do not fully understand, increasing the risk of unintended privilege expansion and downstream misuse if the environment is misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents the DeleteRetention operation, which can change repository data-retention behavior and lead to unintended preservation or deletion outcomes, but it provides no warning about operational impact. Under the markdown criteria for SQP-2, destructive or system-integrity-affecting behaviors should be accompanied by a user warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The shared-domain creation example permits --deadline=forever, enabling durable cross-account read access to a repository without an explicit caution about external exposure. In an image-governance skill, this is security-relevant because it can normalize long-lived sharing and lead to unreviewed data exposure across tenants.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents CreateAgency as a routine step but does not warn that it changes account-level delegation and may grant SWR additional access to other Huawei Cloud services such as OBS or CCE. In an agentic context, this omission can cause users or automation to approve a privilege-affecting action without understanding the security and governance implications.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill documents an operation that causes irreversible automated deletion of image tags, which is a destructive action with material operational impact. Although this is expected platform behavior rather than overtly malicious logic, the workflow presents creation/update commands that can enable unattended cleanup without requiring strong guardrails such as dry-run validation, explicit approval checkpoints, or protected-tag validation.

Content

Scanner excerpt · references/task-retention-management.md (reported line 31)May include surrounding context.

md
### W2: Create a Retention Rule

⚠️ **CAUTION**: When the retention rule executes, image tags not matching the retention conditions are automatically deleted. **Deleted tags cannot be recovered.** Verify the rule conditions carefully before confirming.

Retention rules define which tags to keep. Tags NOT matching any rule condition will be deleted during execution.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cleanup scenario instructs users to delete shared domains after listing them, but the scenario itself does not repeat or place an adjacent warning that deletion immediately breaks external image pull access for the target organization. In an access-governance skill, operators may copy only the scenario block and perform a disruptive action without noticing the earlier caution, causing unintended service interruption or denial of access to downstream users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The verification guide includes live permission-grant and revoke commands against SWR namespaces without an explicit warning that these operations modify production access controls. A user following the checklist in the wrong account, region, or namespace could unintentionally grant repository access to another IAM principal, creating unauthorized access until cleanup occurs or if cleanup is skipped.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation first states that sync rules and triggers belong to another skill and are out of scope. Later, the agency section presents CreateAgency as required for image sync to OBS and CCE trigger deployments, which ties this skill's write capability to exactly those out-of-scope functions and creates an intent contradiction in the docs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The section header says 'ListRetentions (verified)' and provides an empty-array example, but the text immediately below says that when retention rules exist, the response format still needs verification. This is an active contradiction in the file's documentation and could mislead downstream consumers into assuming the full output contract is confirmed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The documentation says the response format is identical to image-management 'ListReposDetails', introducing a cross-reference to a different skill/domain rather than a governance-specific contract. This creates intent ambiguity in the docs by describing a governance output in terms of another skill's image-management response, rather than documenting the actual governance-specific behavior directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The DeleteRepoDomains operation revokes an existing shared access path for another domain, which can disrupt dependent users or systems, yet no warning is included. A brief disclosure would help users understand the immediate access impact before execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The operations catalog includes Chinese-language descriptions such as 获取共享镜像仓库列表 and 创建委托 within an otherwise English document. This imposes a specific language presentation without user opt-in or explanation of why the locale is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.