Back to skill

Security audit

huawei-cloud-swr-image-management

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Huawei SWR management helper, but its CLI installation and credential-handling guidance contains risky patterns that should be reviewed before use.

Install only if you intentionally want an agent to manage Huawei Cloud SWR resources. Before using it, avoid the one-line remote installer unless you independently verify the source, keep hcloud permissions least-privileged, require confirmation for every create/update/delete, treat auth values and decoded Docker credentials as passwords, avoid docker login -p in shared environments, and prefer short-lived tokens over one-year secrets unless CI/CD truly requires them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (30)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The command downloads a shell script from the network and executes it immediately with bash, preventing meaningful inspection and trusting remote content at execution time. In an installation guide for a cloud-management CLI, this is especially dangerous because compromised execution could steal cloud credentials, install persistence, or alter local tooling.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 17)May include surrounding context.

One-click Installation

bash
# Download and run official installation script (interactive)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

# Non-interactive installation (skip confirmation)
curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This variant repeats the same remote script execution pattern and adds -y, making execution unattended and further reducing user visibility into what the installer does. If the hosted script is altered or the distribution channel is compromised, arbitrary code can run silently on the target system.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

### Verify Installation

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases like 'container image', 'docker login', and generic Chinese equivalents that can match requests outside Huawei SWR. In an agentic environment, overbroad activation can route unrelated container tasks into this skill, causing inappropriate command suggestions, credential-handling flows, or destructive SWR operations in the wrong context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L415-L419 repeatedly state that image security scanning is not provided or supported by this skill, yet L417 instructs the agent to query enterprise instance configuration and inspect enableArtifactScanning, which is itself a scanning-related operational capability. This is more than merely incomplete documentation: it actively mixes an unsupported claim with procedural guidance for performing scanning enablement checks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The surrounding unsupported-operations section asserts these capabilities are not supported by this skill, but L424-L428 documents a specific hcloud SWR ShowInstanceArtifactAddition --addition=build_history command to query build history. That is a direct contradiction between the intent statement and the operational instructions provided.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The example pulls docker.io/library/nginx:latest, which is a mutable tag and can change over time. In a container-management skill, this increases supply-chain risk because users may import different image contents than expected, undermining reproducibility and potentially introducing malicious or vulnerable image updates.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/acceptance-criteria.md (reported line 126)May include surrounding context.

Do you want to proceed? (yes/no)

text

**Error:** Execute write operations without confirmation
```bash
# Directly executing Create/Update/Delete without user confirmation is prohibited
hcloud SWR DeleteNamespaces --namespace=pancake --cli-region=cn-north-4

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly instructs users to download and execute a remote shell script, including a non-interactive mode, without requiring integrity verification, script review, or warning about the risks. If the hosting location, transport path, or upstream artifact is compromised, users could execute attacker-controlled code on their systems immediately.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The non-interactive -y mode suppresses user confirmation for a script that is being fetched and executed locally, reducing opportunities to notice unexpected behavior or installation targets. In the context of remote script execution, this increases the likelihood of silent unsafe changes if the installer is modified or behaves unexpectedly.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 19)May include surrounding context.

Download and run official installation script (interactive)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh

Non-interactive installation (skip confirmation)

curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 49)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 71)May include surrounding context.

md
# AMD 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-amd64.tar.gz"
tar -zxvf huaweicloud-cli-linux-amd64.tar.gz
sudo mv hcloud /usr/local/bin/

# ARM 64-bit system
curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 54)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 76)May include surrounding context.

ARM 64-bit system

curl -LO "https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/huaweicloud-cli-linux-arm64.tar.gz" tar -zxvf huaweicloud-cli-linux-arm64.tar.gz sudo mv hcloud /usr/local/bin/

text

### 2. macOS Systems

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document recommends using CreateSecret for CI/CD because it provides long-term credentials valid for one year, but it does not include any warning about secure storage, least-privilege access, rotation, masking in logs, or revocation. In an infrastructure/container registry management skill, this omission can lead users to create durable registry credentials and handle them unsafely, increasing the risk of credential leakage and unauthorized image push/pull operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly instructs decoding a base64 auth field to recover Docker login credentials, but it does not warn that this reveals a secret that should be handled as sensitive data. In a skill specifically designed for SWR image management and docker login workflows, this increases the chance the agent or user will print, log, persist, or otherwise mishandle reusable credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide instructs users to decode an auth token and use docker login -p <decoded_password>, which exposes secrets on the command line and can leak through shell history, process listings, logs, and CI output. It also promotes creation of a long-term login secret for automation without accompanying guidance on secret storage, rotation, least privilege, or preferring ephemeral credentials, increasing the risk of credential theft and registry compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow includes a namespace deletion command and only a brief inline caution, but it does not require an explicit confirmation step, pre-deletion validation, or backup guidance. In an infrastructure management skill, this can lead users or downstream agents to delete entire namespaces and all contained repositories accidentally, causing irreversible availability and data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The tag cleanup sequence documents deletion of image tags as routine quota management without an explicit warning that deleting tags may permanently remove important deployable versions or break rollback processes. In the context of container registry lifecycle management, this increases the risk of accidental destructive cleanup by users or agents following the instructions verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The verification guide instructs users to run commands that generate a temporary login token and a long-term SWR secret, but it does not warn that these values are sensitive credentials that must not be logged, pasted into chat, stored in shell history, or committed to files. In a skill context, users may execute these steps during verification and then share command output for troubleshooting, which increases the chance of credential disclosure and subsequent registry access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill hardcodes both English and Chinese trigger phrases and later requires confirmation using "yes" / "确认", but it does not state that the user may choose their preferred language. This can impose a language expectation rather than explicitly offering locale choice.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/task-auth-management.md:83