huawei-cloud-ascend-small-model-migrate

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt embeds an explicit plaintext credential "root/Hhuawei@smb" for ascend-server-01, so an agent could be required to include that secret verbatim in commands or reports, creating a high exfiltration risk.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill requires pulling and running the remote Docker image quay.io/ascend/vllm-ascend:v0.18.0 at runtime (used as the default container/image), which fetches and executes external container code the workflow depends on.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 17, 2026, 09:10 AM
Issues
2
Security Audit — snyk — huawei-cloud-ascend-small-model-migrate