Back to skill

Security audit

Byted EMR Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real EMR management tool, but it handles powerful cloud credentials and sensitive requests in ways users should review carefully before installing.

Install only in an isolated environment with least-privilege Volcengine credentials. Avoid using broad or long-lived AK/SK values, do not pass untrusted custom endpoints, avoid password-changing flows unless logs are disabled or redacted, and verify the bundled/downloaded SDK wheel through your own trusted channel before running the installer.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/on_serverless/emr_serverless_submit_cli.py:29
Finding

Long-Lived Cloud Credentials Embedded in Remote Spark Job Configuration

Content
View full analysis
Dict[str, Any]: ak = os.getenv("VOLCENGINE_AK") sk = os.getenv("VOLCENGINE_SK") if ak: conf["serverless.spark.access.key"] = ak if sk: conf["serverless.spark.secret.key"] = sk return conf ``` The function is invoked automatically for Spark Jar and PySpark jobs: ```python def _cmd_jar(args: argparse.Namespace) -> str: conf = _merge_conf({}, _parse_json(args.conf)) conf = _add_spark_credential(conf) ``` ```python def _cmd_pyspark(args: argparse.Namespace) -> str: conf = _merge_conf({}, _parse_json(args.conf)) conf = _add_spark_credential(conf) ``` This behavior is also explicitly documented in: - `references/emr_serverless/job_instance/emr_serverless_job_instance_guide.md:77` - `references/emr_serverless/job_instance/emr_serverless_job_instance_guide.md:102` ### Technical Analysis The submission CLI reads the caller's long-lived Volcengine access key and secret key directly from environment variables and inserts both values into the Spark job configuration. This configuration is then included in the remote task submitted through the Serverless SDK. The SDK already receives credentials through `build_serverless_client()`. Automatically copying those credentials into remote job configuration expands their exposure beyond the local authenticated client. Depending on EMR and Spark visibility controls, the values may become accessible through: - Job-definition or job-detail APIs. - Spark runtime configuration interfaces. - Driver or executor logs. - Control-plane request records. - Job history and debugging interfaces. - User-provided Jar or PySpark code running inside the job. The behavior ...[truncated 1571 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/on_serverless/emr_serverless_cli.py:68
Finding

Arbitrary Endpoint Receives Signed Requests and Sensitive Request Bodies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/on_ecs/emr_on_ecs_manager.py:43
Finding

Sensitive API Request Bodies and Responses Logged Without Redaction

Content
View full analysis
{result}") ``` The Serverless manager follows the same pattern: ```python logger.info( f"manage_emr_serverless(service={service}, action={action}, version={version}, region={region}, method={method}, query={query}, body={body}) => {result}") ``` The EMR Agent manager logs complete diagnostic requests and responses: ```python logger.info( f"manage_emr_agent(action={action},region={region}, body={body}) => {result}") ``` The VKE manager also logs complete bodies and results: ```python logger.info( f"emr_on_vke_manager(action={action},region={region}, body={body}) => {result}") ``` The documented ECS user-management operations place plaintext passwords into request bodies, including: - User creation in `references/emr_on_ecs/user/emr_on_ecs_user_guide.md:62`. - Password changes containing `OldPassword` and `NewPassword` in lines `329-342`. ### Technical Analysis The managers interpolate entire Python dictionaries into INFO-level log messages without filtering sensitive fields. Request bodies can contain: - New and old cluster-user passwords. - Custom image repository passwords. - Diagnostic questions and generated reports. - SQL statements and job arguments. - User and group information. - Infrastructure identifiers and configuration values. - Tokens or secrets supplied through generic body fields. Responses are also logged wholesale and may ...[truncated 1467 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/bin/install_serverless_sdk.sh:9
Finding

Downloaded Python Wheel Installed Without Integrity Verification

Content
View full analysis
/dev/null; then echo "从$name下载成功" return 0 else echo "从$name下载失败" rm -f "$LOCAL_WHL_PATH" 2>/dev/null return 1 fi } ``` The downloaded file is installed immediately without hash or signature verification: ```bash if download_file "$PUBLIC_URL" "公网"; then pip install "$LOCAL_WHL_PATH" exit 0 fi if download_file "$INTERNAL_URL" "火山内网"; then pip install "$LOCAL_WHL_PATH" exit 0 fi ``` The bundled local artifact is likewise installed based only on its filename: ```bash if [[ -f "$LOCAL_WHL_PATH" ]]; then echo "使用本地安装包: $LOCAL_WHL_PATH" pip install "$LOCAL_WHL_PATH" exit 0 fi ``` ### Technical Analysis The script trusts any file served under the expected wheel filename. HTTPS protects transport under normal conditions, but it does not provide immutable artifact verification. A compromised storage account, artifact-publishing process, DNS or certificate environment, internal mirror, or modified local wheel can replace the package while retaining the expected filename. Python packages can execute code during installation depending on packaging behavior and will execute package code when later imported. The installed SDK is imported by the Skill's job-submis ...[truncated 1154 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (111)

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.