Security audit
Test Skill 02
Security checks for vulnerabilities and agentic risk
Overview
This skill is a straightforward Huawei Cloud CCE cluster-listing helper with disclosed credential use and no evidence of hidden persistence or destructive behavior.
Install only if you intend to let the skill query your Huawei Cloud CCE inventory. Use a least-privilege IAM credential limited to cluster listing, set credentials through environment variables, and be aware that the submitted artifact describes commands but does not include the referenced Python script.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
