Back to skill

Security audit

volcengine-troubleshooting

Security checks for vulnerabilities and agentic risk

Overview

This VolcEngine troubleshooting skill is mostly disclosed and read-only, but one ALB helper can collect infrastructure details outside the selected load balancer.

Install only if you are comfortable letting the agent use VolcEngine read credentials for troubleshooting. Prefer temporary least-privilege credentials, avoid sharing raw outputs, and be especially careful with the ALB backend collector until its query scope is narrowed to the selected load balancer.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/domain-guides/compute-container-network/scripts/collect_clb_backend_context.py:151
Finding

ALB Collector Enumerates Unrelated VPC Server Groups and Backend Infrastructure

Content
View full analysis

Vulnerability Details

File Location: references/domain-guides/compute-container-network/scripts/collect_clb_backend_context.py, lines 151-196 and 211-231
Vulnerability Type: Least-privilege violation through overbroad cloud-resource enumeration
Risk Level: Medium

Vulnerable Code

python
lbs = list_from(lb_resp, "load_balancers", "LoadBalancers")
vpc_id = (lbs[0].get("vpc_id") or lbs[0].get("VpcId")) if lbs else None
listeners_resp = to_dict(
    alb.describe_listeners(
        volcenginesdkalb.DescribeListenersRequest(
            load_balancer_id=load_balancer_id,
            listener_ids=[listener_id] if listener_id else None,
            page_size=100,
        )
    )
)
server_groups_resp = to_dict(
    alb.describe_server_groups(
        volcenginesdkalb.DescribeServerGroupsRequest(
            vpc_id=vpc_id,
            page_size=100,
        )
    )
)
listeners = list_from(listeners_resp, "listeners", "Listeners")
server_groups = list_from(server_groups_resp, "server_groups", "ServerGroups")
listener_ids = sorted(
    collect_values(listeners, ["listener_id", "ListenerId"])
)
server_group_ids = sorted(
    collect_values(server_groups, ["server_group_id", "ServerGroupId"])
    | collect_values(listeners, ["server_group_id", "ServerGroupId"])
)

health = []
for lid in listener_ids:
    health.append(
        to_dict(
            alb.describe_listener_health(
                volcenginesdkalb.DescribeListenerHealthRequest(
                    listener_ids=[lid],
                    only_un_healthy=False,
                )
            )
        )
    )

attrs = []
for sgid in server_group_ids:
    attrs.append(
        to_dict(
            alb.describe_server_group_attributes(
                volcenginesdkalb.DescribeServerGroupAttributesRequest(
                    server_group_id=sgid
                )
            )
        )
    )

backend_instance_ids = sorted(
    collect_values(attrs, ["instance_id", "InstanceId"])
)

return {
 
...[truncated 3637 chars]
Remediation
View remediation

Remediation Suggestions

  1. Derive server-group IDs only from listeners or forwarding rules associated with the requested ALB.
  2. If the SDK supports a load-balancer-specific filter for DescribeServerGroups, pass the requested load balancer ID rather than querying solely by VPC ID.
  3. Remove the union between listener-associated server groups and every group returned by the VPC-wide query.
  4. Before retrieving server-group attributes, verify that each group is explicitly linked to the requested ALB.
  5. Make complete raw responses opt-in. Return a minimal, redacted summary by default.
  6. Avoid returning unrelated ECS metadata and limit selected fields to those needed for backend-health diagnosis.
  7. Add an explicit maximum number of groups and backend instances that may be inspected.
  8. Add regression tests with at least two ALBs in the same VPC and verify that a query for one ALB never returns the other ALB's server groups or backend instances.
  9. Update the script documentation to describe the exact query scope and any optional raw-output behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (80)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
先把 `SKILL_ROOT` 解析为包含本 `SKILL.md` 的绝对目录。所有脚本和 reference 都从

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/compute-container-network/references/api-coverage-matrix.md (reported line 522)May include surrounding context.

md
| `ListAddons` | `vke` | 资源存在性、状态、配置或诊断证据 |
| `ListClusters` | `vke` | 资源状态、实例/节点/集群运行态证据 |
| `ListInstanceTypeLabels` | `vke` | 资源状态、实例/节点/集群运行态证据 |
| `ListKubeconfigs` | `vke` | 资源存在性、状态、配置或诊断证据 |
| `ListNodePools` | `vke` | 资源状态、实例/节点/集群运行态证据 |
| `ListNodes` | `vke` | 资源状态、实例/节点/集群运行态证据 |
| `ListPermissions` | `vke` | 身份、权限、密钥或授权证据 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 28)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 41)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 47)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 59)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/03-key-permission-access-control/README.md (reported line 29)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/09-playbooks/README.md (reported line 15)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/09-playbooks/README.md (reported line 16)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/api-coverage-matrix.md (reported line 492)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/getting-started.md (reported line 201)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/getting-started.md (reported line 202)May include surrounding context.

  1. 如果 API 可达,再查:
text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 41)May include surrounding context.

text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

注意:DescribeKeys 必须带 KeyringName 或 KeyringID,<keyring-name> 从 DescribeKeyrings 返回中选取。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 47)May include surrounding context.

text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

注意:DescribeKeys 必须带 KeyringName 或 KeyringID,<keyring-name> 从 DescribeKeyrings 返回中选取。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/02-kms-service-key-state/README.md (reported line 59)May include surrounding context.

text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

注意:DescribeKeys 必须带 KeyringName 或 KeyringID,<keyring-name> 从 DescribeKeyrings 返回中选取。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/domain-guides/security-kms-encryption/references/09-playbooks/README.md (reported line 16)May include surrounding context.

text
ve kms DescribeKeyrings --body '{"CurrentPage":1,"PageSize":10}'
ve kms DescribeKeys --body '{"CurrentPage":1,"PageSize":10,"KeyringName":"<keyring-name>"}'

注意:DescribeKeys 必须带 KeyringName 或 KeyringID,<keyring-name> 从 DescribeKeyrings 返回中选取。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/getting-started.md (reported line 201)May include surrounding context.

text
ve kms DescribeKeys
ve kms DescribeKey --KeyringName KEYRING_NAME --KeyName KEY_NAME
ve kms ListKeyVersions --KeyringName KEYRING_NAME --KeyName KEY_NAME
ve seccenter DescribeAlarmEventList
ve waf ListInstances

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/getting-started.md (reported line 202)May include surrounding context.

text
ve kms DescribeKeys
ve kms DescribeKey --KeyringName KEYRING_NAME --KeyName KEY_NAME
ve kms ListKeyVersions --KeyringName KEYRING_NAME --KeyName KEY_NAME
ve seccenter DescribeAlarmEventList
ve waf ListInstances

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says to use the skill whenever the user encounters VolcEngine errors or needs local troubleshooting across a very large set of product areas. This trigger scope is broad and lacks explicit exclusion conditions or negative examples, which could cause the skill to activate for many generic cloud-support conversations beyond its intended boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operational instructions in the skill body are presented in Chinese, which effectively imposes a language requirement on users and operators reading the skill. The file does not offer a language choice or explain that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill guidance is written in Chinese, including the title and operational instructions, with no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This creates a natural-language locale policy issue because it implicitly enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file states that scripts should prioritize reading VOLCENGINE_ACCESS_KEY, VOLCENGINE_SECRET_KEY, and VOLCENGINE_SESSION_TOKEN, which are sensitive credentials. The description does not include any warning about credential sensitivity, safe handling, or privacy implications, so users are not informed about the risks of using environment-based secrets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill documentation is written only in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example maps a balance/renewal question to ListCostAnalysisOpenApi, which conflicts with the document's own guidance that balance checks should use QueryBalanceAcct. In a troubleshooting skill, this can misroute operators to the wrong API, causing incorrect conclusions about account funds or renewal status and potentially exposing unrelated cost data while failing to answer the user’s request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.