Back to skill

Security audit

huawei-cloud-waf-log-analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill can help analyze Huawei Cloud WAF logs, but it also steers users toward high-impact WAF changes with broad permissions and unsafe command templates.

Review before installing. Use the read-only IAM policy by default, and do not grant the full write-capable policy unless you intentionally want this workflow to prepare production WAF changes. Treat generated commands as drafts: rebuild or quote event-derived values safely, validate business impact and rollback steps, and avoid pasting commands directly from logs. Use dedicated least-privilege Huawei Cloud credentials rather than personal or admin AK/SK keys.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:478
Finding

Command injection through unquoted WAF event data in generated remediation commands

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:478-485; references/rule-recommendation-guide.md:105-123, 162-175
Vulnerability Type: Command injection through unsafe command generation
Risk Level: High

Vulnerable Code

From SKILL.md:478-485:

bash
hcloud WAF CreateCustomRule   --policy_id={policy_id} \
  --name={rule_name} \
  --action.category=block \
  --conditions.1.category={field_category} \
  --conditions.1.logic_operation={logic_op} \
  --conditions.1.contents.1={match_value} \
  --priority=50 \
  --time=false

From references/rule-recommendation-guide.md:105-123:

bash
hcloud WAF CreateCustomRule \
  --policy_id={policy_id} \
  --name={rule_name} \
  --action.category=block \
  --conditions.1.category=url \
  --conditions.1.logic_operation=contain \
  --conditions.1.contents.1={targeted_url} \
  --conditions.2.category=params \
  --conditions.2.logic_operation=contain \
  --conditions.2.contents.1={sqli_pattern} \
  --priority=30 \
  --time=false

From references/rule-recommendation-guide.md:162-175:

bash
hcloud WAF CreateCustomRule \
  --policy_id={policy_id} \
  --name={rule_name} \
  --action.category=block \
  --conditions.1.category=user-agent \
  --conditions.1.logic_operation=contain \
  --conditions.1.contents.1={scanner_signature} \
  --priority=31 \
  --time=false

Technical Analysis

The Skill analyzes WAF records whose URL, payload, parameters, and User-Agent values originate from requests made by remote web clients. It then instructs the Agent to generate copy-paste-ready hcloud commands using values such as {targeted_url}, {sqli_pattern}, {scanner_signature}, and {match_value}.

These values are placed directly into shell command arguments without quoting, escaping, strict validation, or structured serialization. A remote requester can therefore place PowerShell metacharacters or statement separators in a logged request field. If that value is reproduced in a recommendation, ...[truncated 2243 chars]

Remediation
View remediation

Remediation Suggestions

  1. Never interpolate WAF event fields directly into shell command strings.
  2. Treat URLs, request parameters, payloads, headers, User-Agent values, hostnames, descriptions, and generated rule names as untrusted.
  3. Generate a structured API request object and serialize it with ConvertTo-Json instead of constructing command text.
  4. Use --cli-jsonInput for attacker-influenced rule values. Write the JSON through a secure, uniquely named file and pass only the trusted file path to hcloud.
  5. Where direct invocation is unavoidable, use PowerShell argument arrays and native process APIs rather than a command string interpreted by PowerShell.
  6. Apply strict allowlists to fields with narrow formats:
    • Validate policy and project identifiers against their documented identifier syntax.
    • Validate IP addresses and CIDR values with dedicated parsers.
    • Restrict country codes to two ASCII letters.
    • Generate rule names locally instead of deriving them from request content.
  7. Reject control characters and shell metacharacters as defense in depth, but do not rely on filtering as a replacement for structured argument passing.
  8. Display all event-derived values separately from executable commands and clearly mark them as untrusted.
  9. Add tests containing PowerShell separators, quotes, substitutions, and newline characters to verify that every value remains a single inert API field.
  10. Apply the same remediation to all corresponding templates in references/rule-recommendation-guide.md, not only the primary template in SKILL.md.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| Aggregate and analyze event data | ✅ YES | Core analysis work |
| Output recommended hcloud commands | ✅ YES | Provide copy-paste ready commands for the user |
| Execute `Create*` / `Update*` / `Delete*` commands | ❌ **NEVER** | These modify production resources; the user decides when and whether to run them |
| Auto-execute any write operation based on analysis findings | ❌ **NEVER** | Even if the recommendation seems obvious, do NOT run it |

**What the agent MUST do:**
1. Perform read-only queries and analysis

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
4. Clearly label each command with its purpose and expected effect

**What the agent MUST NOT do:**
1. Execute any command that creates, modifies, or deletes WAF resources
2. Ask the user "should I execute this for you?" — just present the command and let the user decide
3. Proceed to execute recommendations after presenting them — stop after the report is delivered

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that it runs on Windows PowerShell and that the agent must not use Linux/Unix shell commands. This imposes a platform-specific constraint on all users without presenting it as an opt-in or clearly justifying it as a hard environmental requirement in the activation/description metadata, which can violate the policy against forced user locale/environment assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly markets itself as strictly read-only, but it includes a file deletion command (Remove-Item) that performs a write/destructive action on the local host. While it targets temporary JSON files rather than cloud resources, this breaks the stated safety boundary and could delete unintended files if path handling or globbing is wrong.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 23)May include surrounding context.

md
1. Download the binary for your platform
2. Make executable: `chmod +x hcloud`
3. Move to PATH: `sudo mv hcloud /usr/local/bin/`
4. Verify: `hcloud version`

## Configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide instructs users to enter long-lived Huawei Cloud AK/SK credentials via hcloud configure but does not warn how those secrets are stored, who can read them, or safer alternatives such as least-privilege credentials and secure secret handling. In a cloud-security workflow, this can lead to credential exposure on shared workstations or improper use of overly privileged keys, enabling unauthorized access to cloud resources if the host or config files are compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill metadata frames this as log analysis and recommendations, but the IAM guidance explicitly adds a second phase that includes executing WAF configuration changes. That scope expansion can mislead deployers into granting modification privileges to an analysis-oriented skill, increasing the chance of unnecessary write access and unintended security control changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The recommended full-skill policy grants broad wildcard rule-management permissions and policy update rights across all resources, which exceeds what users would expect from a log-analysis skill. If this skill or its surrounding agent workflow is abused, compromised, or misused, it could alter WAF protections, weaken policies, or create overly permissive or disruptive rules.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide explicitly instructs the agent to generate executable, state-changing WAF administration commands rather than staying within passive log analysis. In an agent context, this expands capability from analysis to security-control modification, creating a risky path to unsafe or unintended blocking, policy changes, or operational disruption if the commands are surfaced or acted on without strict approval boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide recommends blocking actions like blacklist and custom rule creation with direct commands, but does not consistently require confirmation of business impact, rollback planning, or validation against legitimate traffic. In practice, this can lead to self-inflicted denial of service, accidental customer blocking, or policy regressions when operators follow generated commands too quickly during incident response.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document includes broad WAF administration areas such as anti-tamper and anti-leakage configuration that exceed the stated log-analysis purpose. This over-broad scope increases the chance that a user or downstream agent will treat the skill as a general WAF management tool, enabling unnecessary or high-impact configuration changes unrelated to the observed logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The PowerShell compatibility section says the agent 'MUST NOT use Linux/Unix shell commands' and must use PowerShell-native equivalents at all times. Later sections nonetheless present commands in bash code blocks and use backslash line continuations, which actively conflicts with the stated execution guidance for this Windows PowerShell-only skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.