Back to skill

Security audit

huawei-cloud-terraform-generator

Security checks for vulnerabilities and agentic risk

Overview

This is a Huawei Cloud Terraform helper that can create real cloud resources after approval, so it is coherent but should be used with careful credential and cost controls.

Install this only if you want an agent to generate and potentially run Terraform against your Huawei Cloud account. Use least-privilege credentials, review generated Terraform, plan output, costs, security group ports, terraform.tfvars, kubeconfig files, and any cloud-init/systemd services before approving apply or destroy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (734)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should generate Huawei Cloud Terraform configurations and deploy infrastructure resources such as ECS, VPC, databases, storage, DNS, and related cloud services. The actual code does none of that. It is a standalone RabbitMQ consumer that connects to a message broker, consumes queue messages, parses JSON, logs processing, and ack/nacks messages. There is no Terraform generation, no Huawei Cloud API interaction, no infrastructure provisioning, and no approval workflow. This is a clear primary-purpose mismatch rather than a minor implementation detail difference.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear purpose mismatch. The declared description says the skill should generate Huawei Cloud Terraform configurations and execute cloud deployments for infrastructure resources. The supplied code does not generate Terraform, does not interact with Huawei Cloud APIs or infrastructure, and does not implement approval-guided deployment behavior. Instead, it acts as an application-level RabbitMQ producer: it reads broker connection settings from environment variables, connects with pika, declares exchanges/queues, binds routing keys, and continuously sends JSON messages on a timer. These are materially different capabilities and resources from the declared Huawei Cloud Terraform functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
See `reference/guardrails.md` for rules about not fabricating specifications and prices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
See `reference/terraform-generation-guide.md` for detailed file structure and content rules.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
See `reference/terraform-generation-guide.md` for detailed file structure and content rules.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
See `reference/terraform-generation-guide.md` for detailed file structure and content rules.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
See `reference/validation-workflow.md` for detailed validation steps.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
See `reference/validation-workflow.md` for detailed validation steps.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
| Security Group | `reference/VPC-best-practices/VPC-best-practices.md` → "Deploy Security Group" | `ethertype` is required |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

md
| Security Group | `reference/VPC-best-practices/VPC-best-practices.md` → "Deploy Security Group" | `ethertype` is required |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

md
| ECS with EIP | `reference/ECS-best-practices/Deploy-Instance-with-EIP-best-practices.md` | Use `huaweicloud_compute_eip_associate`, `public_ip = .address` |

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · assets/cce/addon-coredns/README.md (reported line 80)May include surrounding context.

:

bash
$ terraform init
  1. Review the Terraform plan:

    bash
    $ terraform plan
    
  2. Apply the configuration:

    bash
    $ terraform apply
    
  3. To clean up the resources:

    bash
    $ terraform destroy
    

Configuration Details

CoreDNS Parameters

The example automatically configures CoreDNS with the following key parameters:

  • Basic Configuration (by parameter basic_json):

    • Automatically preserves all original template basic parameters
    • Maintains default CoreDNS settings for optimal cluster DNS resolution
  • Custom Configuration (by parameter custom_json):

    • Automatically preserves all original template custom parameters
    • Ensures CoreDNS operates with cluster-specific settings
  • Flavor Configuration (by parameter flavor_json):

    • Automatically preserves all original template flavor parameters
    • Maintains resource allocation and performance settings

Also

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/cce/addon-coredns/README.md (reported line 94)May include surrounding context.

md
- Automatically preserves all original template flavor parameters
  - Maintains resource allocation and performance settings

Also you can also customize the parameter values ​for this JSON. This practice only introduces the scenario created
based on the template.

## Note

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/cce/kubenetes/authenticate-with-config/README.md (reported line 5)May include surrounding context.

md
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/cce/kubenetes/authenticate-with-config/README.md (reported line 121)May include surrounding context.

md
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/cce/kubenetes/authenticate-with-config/README.md (reported line 139)May include surrounding context.

md
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/cce/kubenetes/authenticate-with-config/README.md (reported line 151)May include surrounding context.

md
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/cce/kubenetes/authenticate-with-config/main.tf (reported line 87)May include surrounding context.

text
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/rds/reference/CCE-best-practices/Deploy-Kubernetes-and-Authenticate-with-Config-best-practices.md (reported line 496)May include surrounding context.

md
This example provides best practice code for using Terraform to create a complete CCE (Cloud Container Engine)
environment (The cluster with a node, and enable the public EIP access), and automatically generate a Kubernetes
configuration file (`.kube/config`) for external access and management. The generated configuration file enables
seamless integration with kubectl and other Kubernetes tools.

## Prerequisites

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
assets/ecs/instance-provisioners/README.md:74

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
reference/terraform-generation-guide.md:155