Back to skill

Security audit

Harmonyos Dev

Security checks for vulnerabilities and agentic risk

Overview

This HarmonyOS developer skill is mostly documentation, but some reusable examples encourage broad sensitive permissions and plaintext signing-secret patterns without enough safety guidance.

Install only if you want Chinese-language HarmonyOS development guidance. Treat its code samples as starting points, not secure defaults: remove unused permissions, avoid background location and floating windows unless clearly needed, do not store signing passwords or keys in tracked project files, and review network, distributed sync, remote file, and download examples for consent and data-scope issues.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/permission-testing.md:12
Finding

Overprivileged Permission Templates Violate Least-Privilege Principles

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/permission-testing.md:207
Finding

Release Signing Passwords Are Shown as Plaintext Configuration Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (25)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation is presented entirely in Chinese from the title onward, with no indication that other languages are supported or that Chinese is an intentional opt-in choice. Under the policy criteria, forcing a specific language without user choice is a natural-language locale violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad generic terms such as @kit, HAP, HAR, and UIAbility, which can activate the skill during ordinary technical discussion that is not specifically asking for HarmonyOS guidance. Over-broad activation can hijack unrelated conversations, causing the agent to apply this skill's output constraints and content in contexts where it is not appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates a rigid response format and includes language/output behavior requirements without user opt-in, which can override normal assistant behavior once the skill is triggered. In combination with the broad trigger list, this increases the chance that unrelated requests are forced into an unwanted style or language, degrading reliability and potentially bypassing higher-level interaction expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is entirely written in Chinese, including the title and instructional content, with no indication that the language is optional or that the document is intended only for a Chinese-specific audience. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example explicitly serializes local application state and sends it to a target device during continuation, but the markdown provides no warning that user or app data may be transmitted across devices. For documentation files, this omission matters because cross-device transfer can affect privacy and user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown states that data written to the KV store is automatically synced to other devices, but it does not include any caution about privacy, data scope, or user consent. Because this behavior can replicate user or app data beyond the local device, the skill description should warn about the impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example demonstrates reading files from a remote device, which is a privacy-sensitive operation, but the markdown does not warn users or implementers about permissions, user consent, or sensitive data exposure. For markdown files, omission of such a warning is in scope when behavior can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The examples demonstrate sending bearer tokens, enabling cookies, and configuring client certificates/private-key passwords for HTTP requests. The document does not include any caution that these mechanisms may transmit sensitive credentials or session data and should only be used with trusted endpoints and secure storage practices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/media-ai-distributed.md (reported line 270)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/media-ai-distributed.md (reported line 297)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/network-http.md (reported line 22)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/network-http.md (reported line 55)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/network-http.md (reported line 70)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/network-http.md (reported line 90)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/network-http.md (reported line 105)May include surrounding context.

md
// 发起请求
httpRequest.request(
  'https://api.example.com/data',
  {
    method: http.RequestMethod.GET,       // 默认 GET
    header: {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes download examples that open local files and write HTTP response data to caller-supplied paths, which can affect user data and filesystem state. The surrounding documentation explains how to perform the operation but does not warn that the examples create or overwrite files locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document enumerates a broad set of highly sensitive HarmonyOS permissions, including contacts, location, microphone, storage management, floating window, and background location, but provides no least-privilege guidance, justification requirements, or warnings about privacy implications. In a developer skill, this can normalize over-requesting permissions and lead downstream users to copy insecure manifests, increasing the risk of unnecessary data access and privacy-invasive app behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The release signing example shows plaintext password fields and concrete secret-bearing configuration structure without warning that real credentials must never be committed to source control. Developers may copy this pattern directly into build-profile.json5 with actual keystore and key passwords, leading to credential leakage, unauthorized app signing, and supply-chain compromise if the repository is exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes a permissions section listing sensitive capabilities such as camera, microphone, contacts, location, background location, and storage access, but it provides only functional descriptions and no user-facing warning about privacy, consent, or data impact. Under SQP-2 for markdown files, descriptions should warn when behaviors could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file provides instructions for creating a global floating window that can remain visible after app exit, which can materially affect user experience and system behavior. Although the required permission is mentioned, there is no warning about the sensitivity of overlay-style UI, when it is appropriate, or the need to clearly inform users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely presented in Chinese and cites a Chinese-source documentation page, but it does not indicate that the language choice is optional or limited to a China-specific audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire reference is written in Chinese, including headings, comments, and usage descriptions, with no indication that users may choose another language or that the Chinese-only presentation is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, but does not state that the glossary is intended specifically for Chinese-speaking users or offer any language alternative. Under the language/locale policy, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The TTS configuration hard-codes the language to 'zh-CN', which imposes a specific language/locale choice in natural-language content. The document does not indicate that this is optional, user-selectable, or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.