Back to skill

Security audit

volcengine-landing-zone

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Volcengine cloud-setup purpose, but it can run privileged infrastructure changes and has under-scoped handling of custom Terraform packages and credentials.

Install only in a trusted workspace. Before running baseline apply, verify the resolved package source and ensure no workspace baseline shadows a built-in package unexpectedly. Use short-lived least-privilege credentials, review Terraform plans and package contents before apply, and protect or delete any generated administrator password file after first use.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/blueprints/landing-zone-setup/04-log/tos_activate.py:296
Finding

Cloud Credentials Exposed Through Process Command-Line Arguments

Content
View full analysis
/cmdline` or process-listing tools. - Shell history when the helper is invoked manually. - Terraform `local-exec` diagnostics and command logging. - CI/CD job logs, endpoint monitoring, audit collectors, or crash reports. - Process telemetry collected by other software on the execution host. The helper uses these credentials to generate signed HTTPS requests. The outbound destination is restricted by `KNOWN_HOSTS` and `resolve_host()` to the official endpoint `tos.cn-beijing.volcengineapi.com`, so the network request itself is necessary for the declared centralized-logging functionality and is not evidence of arbitrary exfiltration. The weakness is the local credential transport mechanism. This implementation also conflicts with the project's documented security rule in `references/account-factory/guidebook.md`, which requires base credentials to remain off the command line. ### Attack Path 1. The centralized-logging phase assumes a role in the log archive account and obtains temporary cl ...[truncated 1341 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:149
Finding

Workspace Baselines Can Silently Replace Trusted Packages and Execute Privileged Terraform

Content
View full analysis
/baselines//terraform/`, write `terraform.tfvars.json`, and execute Terraform serially inside those isolated run directories. - Built-in and workspace baselines are the same execution unit: both are Terraform packages resolved by name, with workspace `account-factory/baselines/` overriding built-in `assets/blueprints/account-factory/baselines/` when names collide. ``` The workspace-first resolution rule is repeated in `references/account-factory/guidebook.md:237-243`: ```markdown - Resolve package sources by name. Check `account-factory/baselines//` in the workspace first; if it does not exist, fall back to the built-in `blueprints/account-factory/baselines//`. - Each baseline package owns its own provider wiring, and the target identity is decided **inside the package's provider**. The runtime supplies the Terraform base credential through normalized environment variables, and that base identity initiates any package-level `assume_role`. ``` The corresponding schema does not constrain package identifiers to safe names in `references/account-factory/baseline.schema.json:83-87`: ```json "package": { "type": "string", "minLength": 1, "description": "Package identifier. The agent resolves packages by name. Workspace packages under account-factory/baselines/ override built-in packages under blueprints/account-factory/baselines/ when both exist." } ``` ### Technical Analysis The workflow gives workspace packages automatic precedence over built-in packages with the same name. It then executes the selected Terraform package with cloud credentials normalized i ...[truncated 3537 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
- `SKILL_ROOT`: the absolute install root of this skill, which contains this `SKILL.md`. Read-only assets such as built-in blueprints, HTML templates, `tos_acti

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 538)May include surrounding context.

html
<div class="diagram-card" style="margin-bottom: 1.5rem;">
        <svg width="100%" viewBox="0 0 800 320" xmlns="http://www.w3.org/2000/svg" aria-label="企业财务管理模式图">
          <!-- 财务托管模式 -->
          <rect x="40" y="20" width="340" height="280" rx="8" fill="#fafafa" stroke="#d8dee8" stroke-width="1.2" />
          <text x="210" y="50" text-anchor="middle" fill="#1f2328" font-size="15" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" font-weight="600">财务托管模式(推荐)</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 622)May include surrounding context.

html
<text x="500" y="22" font-size="11" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#86909c">目标账号</text>
          <text x="760" y="22" font-size="11" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#86909c">账号内服务</text>

          <!-- IdP -->
          <rect x="16" y="220" width="120" height="72" rx="8" fill="#fafafa" stroke="#d8dee8" stroke-width="1.2"/>
          <text x="76" y="249" text-anchor="middle" font-size="13" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#1f2328">企业自有 IdP</text>
          <text x="76" y="268" text-anchor="middle" font-size="10" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#5b6573">统一身份源</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 631)May include surrounding context.

html
<path d="M 136 256 L 160 256" stroke="#165dff" stroke-width="1.5" stroke-dasharray="4,4" marker-end="url(#arrow-id)"/>
          <text x="148" y="247" text-anchor="middle" font-size="11" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#165dff">SSO</text>

          <!-- Cloud Identity -->
          <rect x="160" y="32" width="250" height="450" rx="10" fill="#eef3fb" stroke="#165dff" stroke-width="1.2"/>
          <text x="285" y="58" text-anchor="middle" font-size="14" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#165dff">火山引擎云身份中心</text>
          <text x="285" y="78" text-anchor="middle" font-size="10" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#5b6573">统一分配权限集,集中管理员工身份</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 653)May include surrounding context.

html
<text x="285" y="437" text-anchor="middle" font-size="10" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#165dff">统一身份生命周期管理</text>
          <text x="285" y="452" text-anchor="middle" font-size="10" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#5b6573">入转调离只需在身份中心一次变更</text>

          <!-- Accounts -->
          <rect x="450" y="32" width="250" height="128" rx="10" fill="#d9ecff" stroke="#0b7bc1" stroke-width="1.2"/>
          <text x="575" y="58" text-anchor="middle" font-size="13" font-weight="600" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#033e63">平台治理账号</text>
          <rect x="468" y="70" width="214" height="46" rx="8" fill="#ffffff" stroke="#165dff" stroke-width="1.2"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 703)May include surrounding context.

html
<rect x="760" y="428" width="150" height="32" rx="8" fill="#ffffff" stroke="#d8dee8" stroke-width="1.2" stroke-dasharray="4,4"/>
          <text x="835" y="448" text-anchor="middle" font-size="11" font-weight="500" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" fill="#5b6573">其他治理能力...</text>

          <!-- Mapping Paths -->
          <path d="M 390 139 C 420 139, 438 93, 468 93" stroke="#165dff" stroke-width="1.5" fill="none" marker-end="url(#arrow-id)"/>
          <path d="M 390 249 C 420 249, 438 238, 468 238" stroke="#165dff" stroke-width="1.5" fill="none" marker-end="url(#arrow-id)"/>
          <path d="M 390 359 C 420 359, 438 383, 468 383" stroke="#165dff" stroke-width="1.5" fill="none" marker-end="url(#arrow-id)"/>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 947)May include surrounding context.

html
<text x="120" y="145" text-anchor="middle" fill="#5b6573" font-size="11" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif">账号名 / 显示名</text>
            <text x="120" y="160" text-anchor="middle" fill="#5b6573" font-size="11" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif">目标 OU / 基础标签</text>

            <!-- Arrow 1 to 2 -->
            <path d="M 200 135 L 260 135" stroke="#165dff" stroke-width="1.5" fill="none" marker-end="url(#arrow-af)" />

            <!-- Stage 2: Create Account -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 972)May include surrounding context.

html
<text x="380" y="315" text-anchor="middle" fill="#5b6573" font-size="11" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif">创建完成后再决定是否继续 baseline</text>

            <!-- Arrow 2 to Result -->
            <path d="M 380 180 L 380 205" stroke="#11a2a2" stroke-width="1.5" fill="none" marker-end="url(#arrow-af-grey)" />

            <!-- Arrow 2 to 3 -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/html/landing-zone-solution-plan.html (reported line 984)May include surrounding context.

html
<text x="720" y="118" text-anchor="middle" fill="#165dff" font-size="14" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" font-weight="600">baseline 选择 / 创建 / 应用</text>
            <text x="720" y="136" text-anchor="middle" fill="#5b6573" font-size="11" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif">可选增强项,用于账号创建后的标准配置</text>

            <!-- Baseline Options -->
            <rect x="580" y="160" width="130" height="50" rx="6" fill="#ffffff" stroke="#165dff" stroke-width="1.2" />
            <text x="645" y="182" text-anchor="middle" fill="#165dff" font-size="12" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" font-weight="600">已有 baseline</text>
            <text x="645" y="198" text-anchor="middle" fill="#5b6573" font-size="10" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif">支持多选与合并</text>

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow requires consolidating a generated administrator password into a user-facing document as the primary deliverable, while only forbidding exposure in chat. In the context of landing-zone bootstrap and administrative access, this makes a high-value credential easier to exfiltrate from artifacts, collaboration channels, backups, and downstream automation that may process the markdown file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is broad enough to match many ordinary cloud-management requests, which can cause the skill to trigger when the user did not specifically intend to enter a high-impact infrastructure workflow. In this skill's context, unintended activation matters because the skill is designed to route automatically into operational paths for landing-zone setup and account/baseline management, increasing the chance of initiating sensitive guidance or execution steps under the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger semantics and direct setup example are written only in Chinese, effectively constraining activation and expected interaction to one language. There is no documented opt-in or statement that the user may choose another language, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
### G1. Solution Confirmation (Initial Landing Zone Setup)
**Trigger**: the user has entered the real execution path for initial setup, and the solution confirmation file has not yet been displayed in this run.
**Action**: before any preflight, credential setup, Terraform, or write action, the first thing you do must be to follow [display-protocol.md](references/display-protocol.md) and put the solution confirmation file `./skills/volcengine-landing-zone/assets/html/landing-zone-solution-plan.html` in front of the user: **open it for the user first**; only if opening is unavailable or fails, degrade to delivering its workspace absolute path plus a short guidance line; only when neither is possible, retell the plan in chat as an explicitly marked degraded fallback. Ask the user to confirm the solution or request changes, then stop and wait. The only allowed outward wording is one short guidance line such as "I have opened the solution confirmation file, please review it in the browser and confirm whether we should proceed". **Do not output a body summary, section-by-section explanation, or key-point rewrite before the file is in front of the user.**
**Forbidden**: before the user explicitly confirms, do not start preflight, do not run init/plan/apply, do not "prepare things in the background first", and do not assume consent just because the user previously said they wanted a landing zone. **Never treat a chat summary or paraphrase of the solution HTML as if the file had been displayed.** The openable HTML file itself must be delivered.
**Self-check**: have I delivered the solution HTML according to the display protocol, rather than merely retelling it in chat, and obtained explicit confirmation from the user? If not, stop now.

#### G1 Output Contract (Must Follow Literally)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents that the agent will write run context and tfvars files, copy baseline packages, and execute terraform init / plan / apply, which can change infrastructure and persist state. Although the steps are described, there is no explicit warning to users that these actions may modify cloud resources and local workspace data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document states that packages use runtime environment credentials and may perform AssumeRole into target member accounts via local-exec and ve CLI. This affects sensitive credentials and account access, but the README does not include an explicit caution about required permissions, credential handling, or the security implications of cross-account operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's operational instructions are written entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code can make a state-changing API call (ActiveTosSvc) using user-supplied cloud credentials without any additional confirmation, dry-run mode, or explicit acknowledgment at the point of execution. In a landing-zone skill, that means a prompt or workflow could trigger unintended service activation and associated governance, billing, or compliance consequences if the user did not clearly intend that change.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The HTML document declares lang="zh-CN", and the visible labels and usage instructions are all written in Simplified Chinese. This imposes a specific language/locale in the output template without any user opt-in or documentation that the skill is intended only for a China-specific or Chinese-language context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
## Minimum Input

- Prefer read-only lookup for `root_ou_id` and do not ask the user for it first
- When an enterprise organization already exists, auto-scan the standard OUs first and inject detected IDs into `existing_*_ou_id`
- Ask for `prefix` only when it is missing. It affects OUs, core accounts, and later default naming
- Ask for `region` only when it is missing. Prefer `VOLCENGINE_REGION`, otherwise default to `cn-beijing`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/landing-zone-setup/01-organization.md (reported line 26)May include surrounding context.

md
## Minimum Input

- Prefer read-only lookup for `root_ou_id` and do not ask the user for it first
- When an enterprise organization already exists, auto-scan the standard OUs first and inject detected IDs into `existing_*_ou_id`
- Ask for `prefix` only when it is missing. It affects OUs, core accounts, and later default naming
- Ask for `region` only when it is missing. Prefer `VOLCENGINE_REGION`, otherwise default to `cn-beijing`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/landing-zone-setup/02-finance.md (reported line 40)May include surrounding context.

md
## Result Notes

- After this phase completes, make it clear which core accounts already have the intended finance relationships
- Finance relationships are not automatically removed when Terraform resources are destroyed. If removal is needed, run `ve billing DeleteFinancialRelation` or an equivalent cleanup command separately

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to read a freshly generated administrator password from a reset result file and copy it inline into a markdown document on disk. Storing bootstrap credentials in a broadly readable, user-facing artifact increases the chance of credential leakage through local filesystem access, source control, backups, logs, or later sharing of the workspace.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/preflight-checks.md (reported line 81)May include surrounding context.

md
- AK/SK credentials from environment variables
- profile-based auth through `profile` / `file_path`, which can also be supplied through `VOLCENGINE_PROFILE` and `VOLCENGINE_FILE_PATH`
- inline provider credentials, which are supported but should not be the default because they write secrets into Terraform configuration

Prefer to mirror the customer's existing operational style at the **source** layer, then normalize the Terraform execution environment into the standard provider runtime environment-variable form documented in the Terraform Provider README at <https://github.com/volcengine/terraform-provider-volcenginecc>. If the customer has no preference, default to reusing an AK/SK-capable credential source such as a named `ve` profile with explicit credentials or existing shell-scoped AK/SK variables.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to automatically create a workspace and sync blueprints into it before real execution, which means local files and directories may be created or overwritten without an explicit user-facing confirmation at that point. In an agent context, silent filesystem modification increases the risk of unintended changes, data clobbering, or operating in the wrong path if path resolution is incorrect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.