Back to skill

Security audit

huawei-cloud-evs-detail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only Huawei Cloud EVS query helper, with no artifact-backed evidence of hidden actions or data exfiltration.

Install only for users who intend agents to read Huawei Cloud EVS disk inventory and monitoring data. Configure the hcloud credentials with the documented read-only IAM permissions, avoid broad account credentials, and review any separately supplied scripts before use because this artifact references wrapper scripts that were not included here.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger 'EVS查询' is overly broad and may cause the skill to activate for unrelated EVS-related requests, including ambiguous or unintended user intents. In an agent environment, overbroad routing can expose cloud inventory and monitoring data to the wrong workflow or cause unintended invocation of external CLI-backed actions, even if the skill is read-only.

Static analysis

No suspicious patterns detected.