Back to skill

Security audit

volcengine-cloud-trail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Volcengine CloudTrail helper whose cloud read and write actions are purpose-aligned and guarded by previews, confirmations, and validation.

Install only if you intend to administer Volcengine CloudTrail. Before confirming any write action, verify the account/profile, region, trail name, delivery target, organization or cross-account scope, and parsed time window; use explicit timezone-bearing timestamps if the default Asia/Shanghai interpretation is not intended.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (31)

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| 底层调用 | `scripts/cloud_trail.py` 封装 `ve cloudtrail <Action>`,版本固定 `2021-09-01` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Credential Access

High
Category
Privilege Escalation
Content
def validate_kms_key_trn(value: str) -> None:
    if not re.fullmatch(r"trn:kms:[^:]+:[^:]+:keyrings/[^/]+/keys/[^/]+", value):
        raise CloudTrailError("TosSSEKMSKeyID 必须是合法 KMS key TRN")
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The skill unconditionally interprets timezone-less timestamps as Asia/Shanghai, which can silently shift the queried audit window when the user or target environment operates in another timezone. In an audit-log investigation context, this can cause missed events, incorrect attribution, or false negatives/positives during incident response because operators may believe they searched the intended time range when they did not.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The entire skill is written in Chinese and instructs the agent on how to interact and summarize actions for users, but it does not provide any user opt-in, alternative language handling, or justification for a Chinese-only locale constraint. Under the policy rule for natural-language violations, this is a language/locale restriction that applies across the whole file.

Static analysis

No suspicious patterns detected.