Huawei Cloud Skill Security Audit Report
Skill: huawei-cloud-css-list
Date: 2026-08-03
====================================================================

1) skillcheck ................... PASS (1 passed, 0 failed)
   - WARNING disclosure.metadata-budget: frontmatter uses ~270 tokens (>~100).
     Accepted: description carries the feature summary + required trigger
     words per Huawei Cloud Skill Specification.
   - No CRITICAL / ERROR findings.

2) markdownlint-cli2 ............ PASS (0 issues in 6 files)
   - Config: .markdownlint.json (repo-consistent)

3) hwcloud-spec (validate-skill.sh)  PASS (PASS: 22  FAIL: 0)
   - Structure, frontmatter, required sections, size/file-count/line-count,
     credential-scan, cross-skill references, one-PR-one-skill.

4) gitleaks ..................... PASS (no leaks in skill directory)
   - Scanned skill dir only: 0 findings. Repo-wide scan reports 3 pre-existing
     leaks in skills/solution/sac/huawei-cloud-sac-new-api/scripts/sensitive_mask.py
     (generic-api-key test values), NOT part of this skill; out of scope.

5) Dependency security .......... NOT EVALUATED
   - pip-audit / safety unavailable in this environment (network restrictions).
     Reported as a missing dependency, not marked passed.
     The skill depends only on the vendor-pinned huaweicloudsdkcss SDK.

VERDICT: PASS (1 accepted warning)
All CRITICAL/HIGH checks green. No ERROR or CRITICAL findings required fixing.
