Back to skill

Security audit

Test Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only Huawei Cloud CCE cluster listing helper, though the referenced script is not included in the artifact.

Install only if you intend to let the agent query your Huawei Cloud CCE inventory. Use an IAM principal limited to cce:cluster:list, provide AK/SK through environment variables only, and review or supply the missing script before relying on the documented commands.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.