Back to skill

Security audit

Huawei Cloud Cce Cluster Upgrade Planner

Security checks across malware telemetry and agentic risk

Overview

This is an upgrade-planning skill, but it places real high-impact Huawei CCE upgrade commands in the normal workflow while presenting them as a preview protected only by instructions.

Install only if you want an agent to help plan Huawei Cloud CCE upgrades and you are prepared to review every generated hcloud command manually. Treat any UpgradeCluster, UpgradeNodePool, UpdateAddonInstance, CreateUpgradeWorkFlow, pause, retry, continue, or cancel command as live production-changing guidance, not as a safe dry run, unless you independently verify the exact hcloud behavior and explicitly approve execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
This planning/evaluation skill embeds direct state-changing operational commands such as UpgradeCluster, Pause/Continue/Retry upgrade tasks, and workflow cancellation. In an agent setting, presenting these commands as normal core actions materially increases the chance that an automation or operator will execute destructive or irreversible upgrade steps when only assessment was intended.

Description-Behavior Mismatch

Low
Confidence
89% confidence
Finding
The documentation categorizes CreateUpgradeWorkFlow under pre-upgrade checking, even though it creates server-side workflow state rather than performing a purely read-only validation. This can mislead an agent or user into triggering a mutating operation under the assumption that it is a harmless inspection step, weakening the safety boundary between analysis and execution.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The skill claims that upgrade execution requires explicit two-step confirmation, but it immediately provides fully executable upgrade commands in the main command set without a technical or structural preview-only barrier. In practice, this relies on documentation discipline alone; an agent or hurried operator may execute the command directly, causing irreversible cluster changes.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims a strict two-step confirmation mechanism, but elsewhere documents directly invocable state-changing upgrade commands without any actual technical guard or separate confirmation token. This creates a deceptive safety model: an agent or user may trust that preview mode is non-destructive and unintentionally trigger irreversible cluster upgrade operations.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill labels Step 5 as a harmless 'preview', but the command shown is the real UpgradeCluster operation, which can initiate an irreversible control-plane upgrade. In a tool-using agent context, this mismatch is highly dangerous because the model may execute the command believing it is only gathering information.

Intent-Code Divergence

Low
Confidence
96% confidence
Finding
The section heading states the reverse upgrade direction (v1.23→v1.21) while the body describes v1.21/v1.19→v1.23 behavior. In an upgrade-planning skill, directionality is safety-critical because operators may apply the wrong prerequisite checks or assume unsupported downgrade semantics, increasing the risk of outage during cluster upgrades.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases include broad English terms like 'cluster upgrade', 'version upgrade', and 'compatibility check', which can cause the skill to activate in unrelated contexts. In an agent environment, overbroad routing increases the chance that Huawei CCE-specific operational guidance and destructive commands are surfaced where they do not apply, raising the risk of accidental misuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.