Back to skill

Security audit

huawei-cloud-vod-collector

Security checks for vulnerabilities and agentic risk

Overview

This feedback collector is mostly coherent, but it can overcollect conversation data, install external login tooling, persist tokens, and publish reports externally with limited user confirmation.

Install only if you are comfortable with automatic feedback capture, quality telemetry unless opted out, external GitCode issue delivery, and helper binaries/tokens stored in your home directory. Before delivery, review and redact feedback files, remove any assistant thinking or full transcripts, verify the configured GitCode repository, and avoid the AtomGit-GO login flow unless you trust that tool and its token storage model.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Natural-Language Policy Violations

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The template explicitly instructs recording assistant chain-of-thought, which is highly sensitive internal reasoning data and not necessary for the stated feedback-collection purpose. Persisting such reasoning can expose hidden deliberative content, increase prompt leakage risk, and violate strong model-safety and privacy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Installing binaries, cloning code, building Go sources, and modifying ~/.local/bin are privileged operational behaviors that are materially different from collecting feedback. Combining them under a benign-seeming collector skill increases the chance of unsafe invocation and environment modification without appropriate scrutiny.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- [references/acceptance-criteria.md](references/acceptance-criteria.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
out): `SKILL_QUALITY_REPORT=0`. **Bootstrapping exception**: `ensure_cli.sh` / `install_cli.sh` are the installers themselves, so they may be executed bare (unw

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template directs operators to store full dialog turns and explicitly preserve assistant chain-of-thought, which exceeds what is necessary for Huawei Cloud issue triage. This creates a direct risk of collecting sensitive user data, internal reasoning, secrets, or policy-sensitive content and then persisting it in feedback records where it may be further accessed, copied, or exported.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Requesting full conversation content without privacy guardrails encourages overcollection of potentially sensitive data, and the chain-of-thought field further amplifies that exposure. Because this is a reusable template, the unsafe collection pattern can be repeatedly propagated across many feedback records, increasing systemic privacy and data handling risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Retaining full dialog content plus assistant chain-of-thought creates a natural-language exfiltration channel in which secrets, personal information, credentials, proprietary prompts, or internal decision traces can be copied into durable records. In the context of a feedback collector, this is more dangerous because users may report failures during sensitive workflows, making transcripts especially likely to contain confidential data.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/install_cli.sh (reported line 31)May include surrounding context.

sh
API_URL="https://skillsapi.developer.myhuaweicloud.com/api/quality/cli/latest"

manifest="$(curl -fsSL --connect-timeout 5 --max-time 20 "${API_URL}")"
v="$(printf '%s' "$manifest" | python3 -c 'import sys,json;print(json.load(sys.stdin)["version"])')"
case "$(uname -m)" in
    x86_64|amd64) plat="linux-x86_64" ;;

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script’s behavior is unrelated to the declared skill purpose of collecting Huawei Cloud user feedback. Instead, it installs external software by cloning a third-party repository, extracting binaries, or compiling source code, which creates a supply-chain execution path hidden behind a benign-seeming skill description. This mismatch is dangerous because users or systems may invoke the skill expecting feedback handling, while it actually modifies the host and introduces untrusted executables.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script clones code from an external repository and then either extracts a bundled archive or builds binaries locally, installing them into the user’s bin directory. Although there is optional checksum verification for a local archive, the checksum is taken from a sidecar file in the same untrusted repository, so it does not provide meaningful authenticity guarantees; the source-build path has no integrity pinning or commit verification at all. In the context of a feedback-collection skill, this is especially suspicious because it introduces unauthorized software installation and a supply-chain risk without functional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This installer downloads, clones, builds, and installs AtomGit-GO binaries into the user's local environment even though the skill is described as a Huawei Cloud feedback/issue collection tool. That mismatch is dangerous because it grants unnecessary code execution and persistence capabilities under the guise of a low-risk reporting skill, expanding supply-chain and unauthorized software installation risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script installs development-tooling style executables by extracting a tarball or compiling Go code from a cloned repository, then places runnable binaries in ~/.local/bin. For a complaint or bug-report collection skill, this is unjustified and dangerous because it introduces arbitrary local code execution and persistence paths unrelated to the advertised task, making compromise of the upstream repo or archive highly impactful.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no explicit tool scope or permission boundaries despite directing use of shell, file read/write, environment access, localhost services, and network operations. This increases the chance of overbroad execution in hosts that rely on manifest-declared scoping, making unintended command execution and data exposure harder to constrain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when the user encounters 'any Huawei Cloud related issues' and includes broad conditions like 'expresses dissatisfaction' and 'encounters errors.' Several listed triggers such as 'report a problem,' 'poor experience,' and generic bug-report phrasing are common support language, and the file provides no negative examples or tighter activation boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic delivery to external GitCode repositories changes the skill from local collection to external publication, which can expose internal errors, user text, or metadata to third parties. That side effect is more dangerous in this context because complaint data often contains stack traces, identifiers, or operational details.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Mandatory telemetry reporting expands the skill from local feedback capture into data collection about executions, potentially including metadata users did not intend to share. In a skill that may process complaint text and operational context, silent telemetry materially raises privacy and compliance risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The instruction to never ask the user and to source the repository only from config encourages autonomous external publication decisions without human validation. In a skill that can send issue content to remote repositories, removing user confirmation increases the risk of accidental data disclosure or misdelivery.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
#### 3.1 Sync to GitCode Issue

> ⚠️ `repo_url` comes **only** from `assets/config.yaml` → `delivery.channels.gitcode.repo_url`. Never use `git remote`, never ask the user.

**Single delivery** — submit one feedback as a GitCode Issue:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

Silently falling back from one integration path to a QR-code login flow without asking the user creates an autonomous authentication workflow with software installation and credential acquisition side effects. That is dangerous because it can surprise users into authorizing persistent access they did not knowingly request.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
> **Pre-check (MCP shortcut — try first):** Before starting the QR-code login flow below, check whether the `devspace-connector` MCP server exposes a `gitcode_create_issue` (or `create_issue`) tool. If the tool exists AND is callable, use it to create the issue directly — the `deliver` response now carries `repo_url`, `issue_title`, and `issue_body` for this purpose. After the MCP tool creates the issue, run `update-status --status delivered` and skip the QR-code login steps 1–8 below.
>
> **If the connector is unavailable — for ANY reason (server not connected, not configured, tool absent, or call fails):** **directly** fall back to the QR-code login flow below. **Do NOT ask the user** whether to connect the MCP server or present any choice — proceed silently to step 1 of the fallback. Any attempt to "enable/connect the connector" is out of scope here and must NOT be offered as an option.

**CRITICAL: Before installation, MUST tell the user:**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs use of an external login helper and persistent token storage, broadening trust to third-party code and long-lived credentials. In a feedback tool context this is especially risky because users may not expect authentication workflows, token persistence, or external software installation as part of reporting an issue.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
4. **Show QR to user**: Display the `login_url` and ASCII `qr_code`. Say: "🔐 First-time login requires AtomGit authorization. Scan the QR code or open the URL in your browser."

5. **Wait for authorization**: `skill-quality-cli run --skill-name huawei-cloud-vod-collector -- python <SKILL_DIR>/scripts/vod_deliver.py login-wait --session-id <session_id>` — blocks until scanned (up to 60s). Do NOT ask the user whether they scanned; just wait.

6. On `SCAN_SUCCESS`, proceed to step 7.

Static analysis

No suspicious patterns detected.