{"data":{"skill":{"slug":"modelarts-agent-huawei-cloud-modelarts-skill","name":"modelarts-skill","icon":"📦","repo":"https://github.com/modelarts-agent/huawei-cloud-modelarts-skill/tree/main/","status":"approved","author":"modelarts-agent","authorVersion":"1.0.0","skillstoreRevision":2},"audit":{"id":"36cf8266-4971-4da5-b542-5f91f48f7440","skill_id":"442013ad-2e58-4eda-88dc-a11834d7810f","version":5,"content_hash":"v3:02be9409c79ca1183f7844009c14d9df684d0cf9:554f325ac909a374b51486ce06cf0c4de1bf9c3f6389b66c0f362359884e8ae4:f275c99a71ad1861a87889c68bd77d106b51b03149d76b8e4c5d33169da3e3db:736b696c6c732f6d6f64656c617274732d6167656e742f6875617765692d636c6f75642d6d6f64656c617274732d736b696c6c:db5b0302ce7bf7837d372cb510cf69fd","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 16 command-execution findings are false positives caused by Markdown backticks in fences, identifiers, and links. However, the documented credential protections cannot be verified because the referenced implementation files are absent.","remediation":[{"issue":"Credential-handling protections are asserted without bundled implementation.","severity":"medium","suggestion":"Include the referenced authentication code and tests, or remove claims that credentials never reach the language model."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":35,"line_start":17},{"file":"SKILL.md","line_end":44,"line_start":35},{"file":"SKILL.md","line_end":54,"line_start":44},{"file":"SKILL.md","line_end":55,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":55},{"file":"SKILL.md","line_end":57,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":59,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":59},{"file":"SKILL.md","line_end":61,"line_start":60},{"file":"SKILL.md","line_end":62,"line_start":61},{"file":"SKILL.md","line_end":63,"line_start":62},{"file":"SKILL.md","line_end":64,"line_start":63},{"file":"SKILL.md","line_end":65,"line_start":64},{"file":"SKILL.md","line_end":71,"line_start":65},{"file":"SKILL.md","line_end":106,"line_start":71}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Unverifiable Credential-Handling Assurance","locations":[{"file":"SKILL.md","line_end":34,"line_start":13}],"confidence":0.96,"description":"The skill promises that credentials never reach the language model and cites auth_manager.py, but the audited package contains no supporting implementation.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The security assurance and implementation reference are explicit, while the audited two-file package contains only SKILL.md and README.md."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":180,"audit_model":"codex","audited_at":"2026-08-09T09:00:56.946+00:00","created_at":"2026-08-11T01:32:10.995579+00:00","static_findings":[{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":35,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":44,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Local Mode** | Reads `MODELARTS_AK/SK/PROJECT_ID/REGION` environment variables |","category":"external_commands","line_end":54,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **notebook, jupyter, image, obs, flavor, cluster, auth** | [`references/notebook.md`](references/n","category":"external_commands","line_end":55,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **pool, resource pool, dedicated pool, node, workload, os network, plugin** | [`references/pool.md","category":"external_commands","line_end":56,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **node pool, nodepool, scale node, node group, plugin, config template** | [`references/node_pool.","category":"external_commands","line_end":57,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **train, training job, 训练任务** | [`references/train.md`](references/train.md) |","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **infer1.0, inference, service, 旧版推理服务,旧版在线服务** | [`references/infer_v1.md`](references/infer_v1.m","category":"external_commands","line_end":59,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **infer2.0, inference, service, 新版推理服务,在线服务,新版在线服务** | [`references/infer_v2.md`](references/infer","category":"external_commands","line_end":60,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **management, workspace, authmode, authorization, quota, tag, scheduled event** | [`references/man","category":"external_commands","line_end":61,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **swr, image repo, 镜像仓库** | [`references/swr.md`](references/swr.md) |","category":"external_commands","line_end":62,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **vpc, virtual private, subnet, security group, 虚拟私有云** | [`references/vpc.md`](references/vpc.md)","category":"external_commands","line_end":63,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **kms, key management, 密钥管理** | [`references/kms.md`](references/kms.md) |","category":"external_commands","line_end":64,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **liteserver, dev server, hyper cluster, hyperinstance, eip, roce** | [`references/liteserver.md`]","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **common, auth, api helper, format result, decorator** | [`references/common.md`](references/commo","category":"external_commands","line_end":71,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":106,"severity":"medium","line_start":71}],"finding_verdicts":[{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"Line 17 opens a fenced diagram block in Markdown. It does not execute a shell or Ruby command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"Line 35 closes the fenced diagram block. The backticks are Markdown syntax without executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"Line 44 uses inline backticks to format environment variable names. No command or interpolation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Line 54 formats a Markdown link label with backticks. It only names a relative reference document.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Line 55 formats a Markdown link label with backticks. It does not invoke an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"Line 56 formats a Markdown link label with backticks. The text is documentation routing only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 formats a Markdown link label with backticks. No executable shell or Ruby context exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Line 58 formats a Markdown link label with backticks. It only points to a relative documentation path.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"Line 59 formats a Markdown link label with backticks. It contains no command execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Line 60 formats a Markdown link label with backticks. The surrounding table is a documentation index.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"Line 61 formats a Markdown link label with backticks. No shell, interpreter, or user input is involved.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"Line 62 formats a Markdown link label with backticks. It identifies a relative VPC reference file.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"Line 63 formats a Markdown link label with backticks. It identifies a relative KMS reference file.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Line 64 formats a Markdown link label with backticks. It does not execute the linked text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Line 65 formats a Markdown link label with backticks. The line is a static documentation table entry.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"Line 71 opens a fenced directory-tree example. The block contains file names and comments, not executable commands.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Unverifiable Credential-Handling Assurance","severity":"medium","locations":[{"file":"SKILL.md","line_end":34,"line_start":13}],"confidence":0.96,"description":"The skill promises that credentials never reach the language model and cites auth_manager.py, but the audited package contains no supporting implementation.","confidence_reasoning":"The security assurance and implementation reference are explicit, while the audited two-file package contains only SKILL.md and README.md."}],"subject_marketplace_commit_sha":"02be9409c79ca1183f7844009c14d9df684d0cf9","subject_content_hash":"554f325ac909a374b51486ce06cf0c4de1bf9c3f6389b66c0f362359884e8ae4","subject_tree_hash":"f275c99a71ad1861a87889c68bd77d106b51b03149d76b8e4c5d33169da3e3db","subject_plugin_path":"skills/modelarts-agent/huawei-cloud-modelarts-skill","audit_payload_hash":"db5b0302ce7bf7837d372cb510cf69fd","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"02be9409c79ca1183f7844009c14d9df684d0cf9","contentHash":"554f325ac909a374b51486ce06cf0c4de1bf9c3f6389b66c0f362359884e8ae4","treeHash":"f275c99a71ad1861a87889c68bd77d106b51b03149d76b8e4c5d33169da3e3db","pluginPath":"skills/modelarts-agent/huawei-cloud-modelarts-skill","auditPayloadHash":"db5b0302ce7bf7837d372cb510cf69fd"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/modelarts-agent-huawei-cloud-modelarts-skill/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}