huawei-cloud-ascend-small-model-migrate
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt embeds an explicit plaintext credential "root/Hhuawei@smb" for ascend-server-01, so an agent could be required to include that secret verbatim in commands or reports, creating a high exfiltration risk.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill requires pulling and running the remote Docker image quay.io/ascend/vllm-ascend:v0.18.0 at runtime (used as the default container/image), which fetches and executes external container code the workflow depends on.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata