Back to skill

Security audit

AWS China What's New

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward AWS China announcements lookup skill that updates a local public-news cache, with some data-quality issues but no evidence of credential theft, persistence, or deception.

Before installing, be comfortable with the skill making outbound requests to www.amazonaws.cn and updating its local JSON cache when data is stale. For important availability or launch-date decisions, verify the linked AWS announcement because a few cached records appear internally mismatched.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · data/whats_new.json (reported line 1166)May include surrounding context.

json
},
  {
    "title": "Amazon MQ now supports OAuth2.0 plugin for RabbitMQ in Amazon Web Services China Regions",
    "body": "<p><a href=\"https://www.amazonaws.cn/en/amazon-mq/\">Amazon MQ</a> now supports OAuth 2.0 authentication and authorization for RabbitMQ brokers with public identity providers in both single instance and highly available Multi-AZ cluster deployments in Amazon Web Services China (Beijing) Region, operated by Sinnet and Amazon Web Services China (Ningxia) Region, operated by NWCD. This feature enables RabbitMQ brokers to authenticate clients and users using JWT-encoded OAuth 2.0 access tokens, providing enhanced security and flexibility in access management.</p>",
    "date": "2025-10-09",
    "link": "/en/new/2025/amazon-mq-supports-oauth2-plugin-for-rabbitmq/",
    "year": 2025

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The entry at L2677 states "EC2 Fleet Added Support for Block Device Mapping Overrides," but the body at L2678 describes a different feature: VPC Block Public Access. This is an active contradiction between the item's title and its documented content, indicating intent/documentation divergence within the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

At L2852 the title refers to "Amazon Elastic Block Store (EBS) now adds full snapshot size information in Console and API," while L2853 discusses an EventBridge Event Bus capability for cross-account delivery. This is a direct contradiction in the inline data documentation for the record.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script presents itself as a query tool but will automatically execute another script that fetches or updates local data whenever the cache is missing or stale. In an agent/skill context, hidden side effects are dangerous because a read-only operation can unexpectedly trigger network access and code execution in another component, expanding trust and attack surface beyond what the caller may intend.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/query.py (reported line 40)May include surrounding context.

python
if need_full:
        print("Data file not found, fetching all years...", file=sys.stderr)
        subprocess.run([sys.executable, FETCH_SCRIPT], check=True,
                       stdout=sys.stderr, stderr=sys.stderr)
    elif need_incremental:
        print("Data stale (>24h), running incremental update...", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/query.py (reported line 44)May include surrounding context.

python
stdout=sys.stderr, stderr=sys.stderr)
    elif need_incremental:
        print("Data stale (>24h), running incremental update...", file=sys.stderr)
        subprocess.run([sys.executable, FETCH_SCRIPT, "--incremental"], check=True,
                       stdout=sys.stderr, stderr=sys.stderr)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON file is a content/manifest-style file, so SQP-3 applies. The body text on L0326 presents an English announcement but links users to a Chinese-language documentation path (/zh_cn/...) without any opt-in or alternative locale, which can violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The record at L500-L501 discusses Aurora PostgreSQL version support, while the link at L503 points to an unrelated QuickSight announcement. This is a clear contradiction between the record's descriptive fields and its target reference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The announcement text is in English, but L1173 includes Chinese-language documentation paths (/zh_cn/...) as the referenced user guides without user opt-in or an English alternative. This imposes a locale choice in natural-language content and fits the SQP-3 language/locale policy category.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and body at L1984-L1985 describe an API Gateway routing-rules feature, but the link at L1987 targets a Lambda inbound IPv6 over PrivateLink announcement. This creates contradictory inline documentation about what the record actually references.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.