T07 · Tool Hijacking and Spoofing
- Location
cli-installation-guide.md:6- Finding
Installation Command Executes an Untrusted Local Script and Uses an Unpinned Download
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a mostly coherent Huawei Cloud CCI query helper, but it needs review because it can persist cloud credentials, expose Kubernetes Secret data, and recommends an unsafe CLI install command.
Install only after reviewing the credential behavior. Use a least-privilege test IAM user, avoid production AK/SK, do not run Secret queries unless explicitly needed, and remove or isolate the hcloud default profile after use. The install command should be corrected to download a verified, pinned installer to a temporary path before execution.
cli-installation-guide.md:6Installation Command Executes an Untrusted Local Script and Uses an Unpinned Download
cci_query.py:179Broad Credential Discovery Persists Secrets in a Shared Default Profile
cci_query.py:158Secret Enumeration Exceeds the Minimum Access Needed for CCI Instance Queries
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Enumerating os.environ.items() to discover credentials is a genuine environment secret harvesting pattern. In this skill, the danger is amplified because the harvested AK/SK are not only used, but then written into the hcloud default profile, creating persistence and increasing the chance of secret exposure or misuse from unrelated environment variables present in the host.
def _load_credentials():
"""动态扫描环境变量获取 AK/SK,不依赖固定变量名。"""
ak, sk = "", ""
for key, value in os.environ.items():
upper = key.upper()
if not (upper.startswith("HUAWEI") or upper.startswith("HW") or upper.startswith("HWC")):
continue
The inline Python command iterates over all environment variables to discover Huawei-related access keys by name pattern. Even though the current snippet only prints OK/MISSING, broad environment harvesting is a dangerous pattern because it normalizes secret discovery from the process environment and can be trivially modified or reused to expose credentials in agent logs or downstream commands.
hcloud --version
python3 -c "import os; ak=[v for k,v in os.environ.items() if k.upper().startswith('HUAWEI') and ('ACCESS_KEY' in k.upper() or k.upper().endswith('_AK'))]; print('AK:', 'OK' if ak else 'MISSING')"
## 2. 认证验证
The skill exposes shell and environment-variable access semantics but does not declare an explicit tool scope such as allowed-tools or permissions. In an agent ecosystem, this weakens policy enforcement and can let the skill invoke broader shell capabilities than reviewers or orchestrators expect, especially since it configures CLI credentials and executes external commands.
This markdown file presents all acceptance criteria exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The documentation includes Pod log access and elsewhere includes Secret access, but provides no warning that these resources may contain credentials, personal data, tokens, or internal system details. In a troubleshooting-oriented skill, users may assume all read operations are low risk, so omitting sensitivity warnings increases the chance of unintended exposure and over-collection of confidential data.
The skill is described as a read-only CCI instance-detail query tool, but the reference expands into listing and reading Secret resources. Even without write actions, Secret enumeration and retrieval can expose credentials, tokens, and other sensitive material well beyond the stated Pod/instance troubleshooting scope, creating a privilege/scope mismatch that can lead to data disclosure.
The reference includes cluster-level RBAC enumeration via ClusterRole listing, which is broader than the manifest's stated instance-detail/read-only troubleshooting purpose. Exposing RBAC inventory enables reconnaissance of permissions and cluster security structure, increasing the usefulness of the skill for environment mapping even if no direct modification is possible.
The script exposes list-secrets, which can retrieve Kubernetes Secret objects. Even if the skill is described as 'read-only', reading secrets is highly sensitive because it may disclose credentials, tokens, certificates, or other confidential material, and this exceeds the implied low-risk inventory/query scope.
The script harvests cloud credentials from the environment and then applies them without a clear user-facing warning about discovery, persistence, and scope. In a skill context, this is dangerous because users may reasonably expect a simple query tool, not one that searches for credentials and stores them into CLI configuration.
The skill claims to perform only read-only cloud queries, but _configure_profile performs a local state-changing operation by writing credentials into the hcloud default profile. This mismatch matters because it persists secrets and modifies user configuration, expanding the blast radius beyond a transient read operation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"--cli-access-key=" + ak,
"--cli-secret-key=" + sk,
]
proc = subprocess.run(
cmd, input="y\n", capture_output=True, text=True, timeout=HCLOUD_TIMEOUT
)
if proc.returncode != 0:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"--cli-access-key=" + ak,
"--cli-secret-key=" + sk,
]
proc = subprocess.run(
cmd, input="y\n", capture_output=True, text=True, timeout=HCLOUD_TIMEOUT
)
if proc.returncode != 0:
The guide instructs users to place AK/SK credentials directly on the command line via hcloud configure set, including an example with literal secret values, but does not warn that command-line arguments may be exposed through shell history, process listings, terminal logs, or persisted CLI configuration files. In a cloud environment, leaked AK/SK can enable unauthorized API access across the account scope granted to that IAM principal, making this more dangerous than an ordinary documentation omission.
The guide recommends exporting AK/SK as environment variables and states that the script will automatically scan multiple variable-name patterns for credentials, but it does not explain that environment variables can be exposed through subprocess inheritance, debugging output, crash reports, CI logs, or misconfigured runtime environments. Automatic broad scanning also increases the chance of unintentionally picking up credentials from unrelated contexts, which can lead to accidental use or disclosure of sensitive cloud secrets.
The natural-language description and expected outputs are consistently specified in Chinese, which implies a fixed language/locale expectation for the skill and its tests. The file does not indicate that users may choose another language or that the Chinese-only behavior is a documented, region-specific requirement.
The verification steps instruct operators to configure AK/SK credentials and invoke real Huawei Cloud APIs, but they do not warn that these are sensitive secrets or that the commands will contact live cloud services. In a skill execution context, this can lead to unintended credential exposure in shell history/logs and unintentional access to production resources during 'verification'.
The function scans the full environment for any variables resembling Huawei credentials instead of consuming narrowly scoped, explicitly named inputs. That broad credential discovery behavior is more powerful than necessary for a query helper and can unintentionally collect secrets from unrelated execution contexts.
This markdown file contains user-facing instructional content only in Chinese, including headings and workflow descriptions, with no indication that users may choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.
This markdown file is natural-language documentation, and all user-facing content is presented only in Chinese. Under the policy rule for language or locale violations, forcing a specific language without user opt-in can be a policy issue when no alternative language option or justification is provided.
This markdown file uses Chinese throughout, but does not state that the skill or report is China-region-specific or that the language was chosen with user opt-in. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.
The file's natural-language instructions and headings are fully Chinese, which can amount to a language policy issue when the skill forces a specific language without user opt-in. There is no note that the skill is region-specific or that alternative language support is unavailable by design.
No suspicious patterns detected.