Back to skill

Security audit

Huawei Cloud CCI Query

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent Huawei Cloud CCI query helper, but it needs review because it can persist cloud credentials, expose Kubernetes Secret data, and recommends an unsafe CLI install command.

Install only after reviewing the credential behavior. Use a least-privilege test IAM user, avoid production AK/SK, do not run Secret queries unless explicitly needed, and remove or isolate the hcloud default profile after use. The install command should be corrected to download a verified, pinned installer to a temporary path before execution.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
cli-installation-guide.md:6
Finding

Installation Command Executes an Untrusted Local Script and Uses an Unpinned Download

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
cci_query.py:179
Finding

Broad Credential Discovery Persists Secrets in a Shared Default Profile

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
cci_query.py:158
Finding

Secret Enumeration Exceeds the Minimum Access Needed for CCI Instance Queries

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
90% confidence
Finding

Enumerating os.environ.items() to discover credentials is a genuine environment secret harvesting pattern. In this skill, the danger is amplified because the harvested AK/SK are not only used, but then written into the hcloud default profile, creating persistence and increasing the chance of secret exposure or misuse from unrelated environment variables present in the host.

Content

Scanner excerpt · cci_query.py (reported line 182)May include surrounding context.

python
def _load_credentials():
    """动态扫描环境变量获取 AK/SK,不依赖固定变量名。"""
    ak, sk = "", ""
    for key, value in os.environ.items():
        upper = key.upper()
        if not (upper.startswith("HUAWEI") or upper.startswith("HW") or upper.startswith("HWC")):
            continue

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
93% confidence
Finding

The inline Python command iterates over all environment variables to discover Huawei-related access keys by name pattern. Even though the current snippet only prints OK/MISSING, broad environment harvesting is a dangerous pattern because it normalizes secret discovery from the process environment and can be trivially modified or reused to expose credentials in agent logs or downstream commands.

Content

Scanner excerpt · verification-method.md (reported line 10)May include surrounding context.

hcloud --version

AK/SK 环境变量已设置且非空

python3 -c "import os; ak=[v for k,v in os.environ.items() if k.upper().startswith('HUAWEI') and ('ACCESS_KEY' in k.upper() or k.upper().endswith('_AK'))]; print('AK:', 'OK' if ak else 'MISSING')"

text

## 2. 认证验证

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes shell and environment-variable access semantics but does not declare an explicit tool scope such as allowed-tools or permissions. In an agent ecosystem, this weakens policy enforcement and can let the skill invoke broader shell capabilities than reviewers or orchestrators expect, especially since it configures CLI credentials and executes external commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all acceptance criteria exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes Pod log access and elsewhere includes Secret access, but provides no warning that these resources may contain credentials, personal data, tokens, or internal system details. In a troubleshooting-oriented skill, users may assume all read operations are low risk, so omitting sensitivity warnings increases the chance of unintended exposure and over-collection of confidential data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a read-only CCI instance-detail query tool, but the reference expands into listing and reading Secret resources. Even without write actions, Secret enumeration and retrieval can expose credentials, tokens, and other sensitive material well beyond the stated Pod/instance troubleshooting scope, creating a privilege/scope mismatch that can lead to data disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The reference includes cluster-level RBAC enumeration via ClusterRole listing, which is broader than the manifest's stated instance-detail/read-only troubleshooting purpose. Exposing RBAC inventory enables reconnaissance of permissions and cluster security structure, increasing the usefulness of the skill for environment mapping even if no direct modification is possible.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script exposes list-secrets, which can retrieve Kubernetes Secret objects. Even if the skill is described as 'read-only', reading secrets is highly sensitive because it may disclose credentials, tokens, certificates, or other confidential material, and this exceeds the implied low-risk inventory/query scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script harvests cloud credentials from the environment and then applies them without a clear user-facing warning about discovery, persistence, and scope. In a skill context, this is dangerous because users may reasonably expect a simple query tool, not one that searches for credentials and stores them into CLI configuration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims to perform only read-only cloud queries, but _configure_profile performs a local state-changing operation by writing credentials into the hcloud default profile. This mismatch matters because it persists secrets and modifies user configuration, expanding the blast radius beyond a transient read operation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cci_query.py (reported line 208)May include surrounding context.

python
"--cli-access-key=" + ak,
        "--cli-secret-key=" + sk,
    ]
    proc = subprocess.run(
        cmd, input="y\n", capture_output=True, text=True, timeout=HCLOUD_TIMEOUT
    )
    if proc.returncode != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · cci_query.py (reported line 244)May include surrounding context.

python
"--cli-access-key=" + ak,
        "--cli-secret-key=" + sk,
    ]
    proc = subprocess.run(
        cmd, input="y\n", capture_output=True, text=True, timeout=HCLOUD_TIMEOUT
    )
    if proc.returncode != 0:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to place AK/SK credentials directly on the command line via hcloud configure set, including an example with literal secret values, but does not warn that command-line arguments may be exposed through shell history, process listings, terminal logs, or persisted CLI configuration files. In a cloud environment, leaked AK/SK can enable unauthorized API access across the account scope granted to that IAM principal, making this more dangerous than an ordinary documentation omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide recommends exporting AK/SK as environment variables and states that the script will automatically scan multiple variable-name patterns for credentials, but it does not explain that environment variables can be exposed through subprocess inheritance, debugging output, crash reports, CI logs, or misconfigured runtime environments. Automatic broad scanning also increases the chance of unintentionally picking up credentials from unrelated contexts, which can lead to accidental use or disclosure of sensitive cloud secrets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language description and expected outputs are consistently specified in Chinese, which implies a fixed language/locale expectation for the skill and its tests. The file does not indicate that users may choose another language or that the Chinese-only behavior is a documented, region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The verification steps instruct operators to configure AK/SK credentials and invoke real Huawei Cloud APIs, but they do not warn that these are sensitive secrets or that the commands will contact live cloud services. In a skill execution context, this can lead to unintended credential exposure in shell history/logs and unintentional access to production resources during 'verification'.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function scans the full environment for any variables resembling Huawei credentials instead of consuming narrowly scoped, explicitly named inputs. That broad credential discovery behavior is more powerful than necessary for a query helper and can unintentionally collect secrets from unrelated execution contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, including headings and workflow descriptions, with no indication that users may choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is natural-language documentation, and all user-facing content is presented only in Chinese. Under the policy rule for language or locale violations, forcing a specific language without user opt-in can be a policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout, but does not state that the skill or report is China-region-specific or that the language was chosen with user opt-in. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language instructions and headings are fully Chinese, which can amount to a language policy issue when the skill forces a specific language without user opt-in. There is no note that the skill is region-specific or that alternative language support is unavailable by design.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.