Back to skill

Security audit

huawei-cloud-waf-policy-manage

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Huawei Cloud WAF import tool, but it asks users to grant and exercise broader live WAF mutation and deletion authority than its import-focused purpose needs.

Review before installing. Use a test account or non-production WAF policy first, avoid the wildcard IAM examples, grant only the exact query/create/update/delete permissions needed for the chosen workflow, export or back up existing policies before overwrite, and require explicit confirmation for any rule or policy deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill contains conflicting instructions for UpdatePolicy handling: the main workflow says to perform differential updates and skip unsupported modules, while the Notes section instructs unconditional mapping of all module_status entries to --options.* parameters. In practice, an agent following the Notes can send unsupported or unnecessary module updates, causing failed imports, policy misconfiguration, or unsafe partial-execution states during overwrite operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation describes creating, updating, deleting, and batch-applying WAF policies and rules without any warning that these actions can materially change production security controls. In an infrastructure-management skill, missing safety warnings increases the chance of accidental destructive or security-weakening changes, especially for overwrite/import flows that may replace existing protections at scale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill focused on importing WAF protection policies from JSON files, creating new policies from JSON, or overwriting existing ones. This diagram documents general CRUD policy management including listing, showing, updating, and deleting policies, which materially exceeds the stated import-oriented scope and suggests broader behavior than claimed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest positions the skill as importing policies from exported JSON, but the diagram presents direct rule-creation workflows for many rule types such as CC, geoip, whitelist/blacklist, anticrawler, and anti-tamper. Those are broader management capabilities rather than merely implementation details of a JSON import skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented IAM policy grants waf:policy:delete even though the skill’s stated purpose is importing policies by creating new ones or overwriting existing ones. Including delete permission expands the blast radius unnecessarily: if the credentials are misused or the skill behaves incorrectly, existing WAF policies could be removed, causing protection gaps or service disruption.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation recommends broad rule-management permissions, including waf:rule:create, delete, update, and especially the wildcard form waf:rule:*, without clearly tying them to the import skill’s minimum operational needs. Over-privileged IAM guidance can lead users to grant excessive authority, enabling unintended or malicious modification/removal of WAF rules and materially weakening application protection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section documents state-changing WAF commands, including policy creation, update, and deletion, with only minimal inline caution and no prominent warning that these operations modify live cloud security configuration and can create or destroy billable resources. In a verification guide for an automation skill, users may run these commands against production by mistake, causing policy drift, accidental outages, or loss of protections.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The rule-creation examples actively alter WAF behavior by creating blocking, logging, filtering, anti-crawler, anti-tamper, anti-leakage, and reputation rules, yet the section does not clearly warn that these can affect real user traffic, trigger false positives, or change enforcement behavior on protected applications. In the context of a policy import/management skill, these examples could be copied directly into live environments and cause service disruption or unintended blocking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The test definition for a skill whose stated purpose is importing WAF policies from JSON includes broad create, update, rule-management, and delete operations unrelated to validating JSON import behavior. This unnecessarily expands the operational scope of the skill and increases the chance that users or downstream automation invoke privileged WAF actions outside the intended import use case, causing configuration drift or unintended security changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including a DeletePolicy test in a JSON import skill introduces destructive capability that is not justified by the skill's declared function. Even with a confirmation flag, the presence of a deletion path increases the risk of accidental or automated removal of active WAF policies, potentially weakening protections or causing service disruption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy issues. Several rule labels are presented only in Chinese while the rest of the document is in English, with no explanation that the skill is region-specific or that users may choose their preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing content that switches from English to Chinese, such as Chinese section headings and operational guidance, but does not state that the skill is intended for Chinese-speaking users or offer a language option. That can violate language/locale policy expectations when users are not given an explicit choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The cleanup section references deleting all test rules via batch or individual deletion without a clear destructive-operation warning or guidance to verify targets before removal. Even if framed as cleanup, bulk deletion can remove legitimate WAF protections if the wrong policy or rule set is selected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.