Queries Huawei Cloud monitoring and enterprise project resources (CES/EPS). Covers alarm rules, alarm histories, alarm templates, dashboards, notification ma...
Documents
huawei-cloud-hss-query
Try itQuery and manage Huawei Cloud HSS (Host Security Service) for daily security inspection and incident response. Covers host assets, vulnerabilities, security baselines, intrusion alerts (trojan/brute-force), login audit logs, risk scoring, and alert handling status updates. Read-only queries plus alert status marking — no isolation or antivirus actions. Use this skill when the user needs to inspect host security risks, investigate suspected intrusion, review vulnerability/baseline reports, or handle security alerts. Triggers include: 主机安全, HSS, Host Security Service, 安全巡检, 漏洞查询, 安全基线, 入侵告警, 木马检测, 暴力破解, 登录审计, 告警处置, 风险诊断, host security inspection, vulnerability scan, baseline check, intrusion alert, trojan detection, brute force, login audit, alert handling, risk diagnosis, security event response.
What it does
Query and manage Huawei Cloud HSS (Host Security Service) for daily security inspection and incident response. Covers host assets, vulnerabilities, security baselines, intrusion alerts (trojan/brute-force), login audit logs, risk scoring, and alert handling status updates. Read-only queries plus alert status marking — no isolation or antivirus actions. Use this skill when the user needs to inspect host security risks, investigate suspected intrusion, review vulnerability/baseline reports, or handle security alerts. Triggers include: 主机安全, HSS, Host Security Service, 安全巡检, 漏洞查询, 安全基线, 入侵告警, 木马检测, 暴力破解, 登录审计, 告警处置, 风险诊断, host security inspection, vulnerability scan, baseline check, intrusion alert, trojan detection, brute force, login audit, alert handling, risk diagnosis, security event response.
The skill document
Huawei Cloud HSS Host Security Skill
Overview
This skill provides AI Agent capabilities for Huawei Cloud HSS (Host Security Service / 主机安全服务), covering daily security inspection, risk diagnosis, and alert handling. It supports querying host assets, vulnerabilities, security baselines, intrusion alerts (trojans, brute-force attacks), and login audit logs, plus updating alert handling status — all via hcloud CLI.
Scope boundaries:
- ✅ Query: host assets, vulnerabilities, baselines, intrusion alerts, login audit logs
- ✅ Diagnose: risk scoring, high-risk vulnerability analysis, abnormal login analysis
- ✅ Manage: update alert handling status (mark as handled, ignored, etc.)
- ❌ Does NOT create or delete host resources
- ❌ Does NOT execute isolation, antivirus, or other high-risk actions
- ❌ Does NOT perform real-time blocking or kill processes
Prerequisites
- hcloud CLI installed and authenticated with valid AK/SK credentials.
- Installation guide: see
references/cli-installation-guide.md - Verify:
hcloud configure listshows a valid profile
- Installation guide: see
- HSS agent deployed on target ECS instances (HSS must be enabled in the console)
- IAM permissions: HSS read permissions for query operations, HSS write permissions for alert handling.
- See
references/iam-policies.mdfor least-privilege policy
- See
- Region: HSS is region-specific. Use
--cli-regionto specify the target region (e.g.,{your-region})
Workflow
1. Identify target → region, project_id, optional host_id filter
2. Query phase → list assets / vulnerabilities / baselines / alerts / login logs
3. Diagnose phase → risk score, high-risk items, abnormal login patterns
4. Handle phase → update alert handling status (requires user confirmation)
5. Output → structured JSON risk list + readable summary report
Core Commands
1. Host Assets (主机资产)
List all protected hosts with agent status, OS type, and risk flags:
hcloud HSS ListHostStatus --cli-region={region} --project_id={project_id} \
[--host_id={host_id}] [--host_name={host_name}] [--os_type={linux|windows}] \
[--agent_status={installed|not_installed|online|offline}] \
[--has_vul=true] [--has_intrusion=true] [--has_baseline=true] \
[--asset_value={important|common|test}] [--limit=10] [--offset=0]
Show host statistics (total hosts, protected count, risk distribution):
hcloud HSS ShowHostsStatistics --cli-region={region} --project_id={project_id}
Query risk status for specific hosts:
hcloud HSS ListHostsRisk --cli-region={region} --project_id={project_id} \
--host_id_list.1={host_id_1} [--host_id_list.2={host_id_2}]
2. Vulnerabilities (漏洞)
List all vulnerabilities with filtering by type, status, severity:
hcloud HSS ListVulnerabilities --cli-region={region} --project_id={project_id} \
[--vul_id={vul_id}] [--vul_name={vul_name}] [--cve_id={cve_id}] \
[--type={linux_vul|windows_vul|web_cms|app_vul|urgent_vul}] \
[--status={vul_status}] [--handle_status={handle_status}] \
[--repair_priority={critical|high|medium|low}] \
[--asset_value={important|common|test}] [--limit=10] [--offset=0]
List vulnerabilities on a specific host:
hcloud HSS ListHostVuls --cli-region={region} --project_id={project_id} \
--host_id={host_id} [--type={linux_vul|windows_vul|web_cms|app_vul|urgent_vul}] \
[--limit=10] [--offset=0]
List hosts affected by a specific vulnerability:
hcloud HSS ListVulHosts --cli-region={region} --project_id={project_id} \
--type={linux_vul|windows_vul|web_cms|app_vul|urgent_vul} --vul_id={vul_id} \
[--limit=10] [--offset=0]
Show vulnerability details (choose by type):
# Linux vulnerability
hcloud HSS ShowLinuxVulDetail --cli-region={region} --project_id={project_id} \
--vul_id={vul_id} --limit=10 --offset=0
# Windows vulnerability
hcloud HSS ShowWindowsVulDetail --cli-region={region} --project_id={project_id} \
--vul_id={vul_id} --limit=10 --offset=0
# Web-CMS vulnerability
hcloud HSS ShowCmsVulDetail --cli-region={region} --project_id={project_id} \
--vul_id={vul_id} --limit=10 --offset=0
Show vulnerability statistics:
hcloud HSS ShowVulStatics --cli-region={region} --project_id={project_id}
3. Security Baselines (安全基线)
Show baseline check overview (last check time, check stats, pass rate, top risks):
hcloud HSS ShowBaselineOverview --cli-region={region} --project_id={project_id}
Show baseline statistics:
hcloud HSS ShowBaselineStatistic --cli-region={region} --project_id={project_id}
List hosts affected by a specific baseline check rule:
hcloud HSS ListHostCheckRules --cli-region={region} --project_id={project_id} \
--check_name={check_name} --standard={cn_standard|hw_standard} --host_id={host_id} \
[--check_rule_name={rule_name}] [--limit=10] [--offset=0]
⚠️
--standard为必填参数。
Show security check report for a specific host:
hcloud HSS ShowSecurityCheckHostReport --cli-region={region} --project_id={project_id} \
--host_id={host_id} --scan_time={scan_time_ms}
⚠️
--scan_time为必填参数(毫秒级时间戳)。
Show risk configuration detail:
hcloud HSS ShowRiskConfigDetail --cli-region={region} --project_id={project_id} \
--check_name={check_name} --standard={cn_standard|hw_standard} \
[--host_id={host_id}]
⚠️
--standard为必填参数(cn_standard=等保合规标准,hw_standard=云安全实践标准)。
4. Intrusion Alerts — Trojan & Malware (木马/恶意软件告警)
Query alert event history with filtering by event type, severity, handling status:
hcloud HSS ListEventHandleHistory --cli-region={region} --project_id={project_id} \
[--event_type={event_type}] [--event_class_ids.1={event_class_id}] \
[--severity={critical|high|medium|low}] [--handle_status={handled|unhandled}] \
[--host_ip={ip}] [--host_name={name}] [--attack_tag={tag}] \
[--asset_value={important|common|test}] [--limit=10] [--offset=0]
Common event_class_ids for malware:
| event_class_id | Description |
|---|---|
av_1002 | Virus (病毒) |
av_1003 | Worm (蠕虫) |
av_1004 | Trojan (木马) |
av_1005 | Botnet (僵尸网络) |
av_1006 | Backdoor (后门) |
av_1010 | Rootkit |
av_1011 | Ransomware (勒索软件) |
av_1015 | Webshell |
av_1016 | Mining software (挖矿软件) |
List host protection history:
hcloud HSS ListHostProtectHistoryInfo --cli-region={region} --project_id={project_id} \
--start_time={start_time_ms} --end_time={end_time_ms} [--limit=10] [--offset=0] \
[--host_id={host_id}] [--file_path={path}]
⚠️
--start_time/--end_time为必填参数(毫秒级时间戳,相差不超过 30 天);--host_id可选。
List antivirus-protected hosts:
# List antivirus-protected hosts (scan_type: quick/full; start_type: now/period)
hcloud HSS ListAntiVirusHost --cli-region={region} --project_id={project_id} \
--limit=10 --offset=0 --scan_type={quick|full} --start_type={now|period} \
[--host_id={host_id}] [--policy_id={policy_id}]
⚠️
--limit/--offset/--scan_type/--start_type为必填参数。--scan_type枚举:quick(快速扫描)/full(全盘扫描);--start_type枚举:now(立即启动)/period(周期启动)。其他值(如all/manual/auto)会被 API 静默忽略并返回空结果。
5. Intrusion Alerts — Brute Force (暴力破解告警)
Query brute-force attack events (login_0001 = attempt, login_0002 = success):
hcloud HSS ListEventHandleHistory --cli-region={region} --project_id={project_id} \
--event_class_ids.1=login_0001 --event_class_ids.2=login_0002 \
[--severity={critical|high|medium|low}] [--handle_status={handled|unhandled}] \
[--host_ip={ip}] [--limit=10] [--offset=0]
List weak password detection results:
hcloud HSS ListWeakPasswordUsers --cli-region={region} --project_id={project_id} \
[--host_id={host_id}] [--limit=10] [--offset=0]
6. Login Audit Logs (登录审计日志)
Query common login IPs:
hcloud HSS ListLoginCommonIp --cli-region={region} --project_id={project_id} \
[--ip_addr={ip}]
Query common login locations:
hcloud HSS ListLoginCommonLocation --cli-region={region} --project_id={project_id} \
[--area_code={area_code}]
⚠️ 这两个操作仅支持
--ip_addr/--area_code过滤器(实测--host_id/--limit/--offset不支持),不可加分页参数。
7. Risk Diagnosis (风险诊断)
Query overall risk score:
hcloud HSS ShowRiskScore --cli-region={region} --project_id={project_id}
Query risk status for specific hosts:
hcloud HSS ListHostsRisk --cli-region={region} --project_id={project_id} \
--host_id_list.1={host_id_1}
8. Update Alert Handling Status (告警处置) — ⚠️ Mutating, Requires Confirmation
Handle alert events (mark as handled, ignored, etc.):
hcloud HSS ChangeEvent --cli-region={region} --project_id={project_id} \
--operate_event_list.1.event_class_id={event_class_id} \
--operate_event_list.1.event_id={event_id} \
--operate_event_list.1.event_type={event_type} \
--operate_event_list.1.occur_time={occur_time_ms} \
--operate_type={operate_type}
⚠️
--operate_type是顶层参数(不属于 operate_event_list 数组内);数组中event_class_id/event_id/event_type/occur_time均必填。
operate_type values for ChangeEvent:
mark_as_handled— Mark as handled (标记已处理)ignore— Ignore (忽略)add_to_alarm_whitelist— Add to alarm whitelist (加入告警白名单)add_to_login_whitelist— Add to login whitelist (加入登录白名单)unhandle— Restore to unhandled (恢复未处理)do_not_ignore— Cancel ignore (取消忽略)remove_from_alarm_whitelist— Remove from alarm whitelist (删除告警白名单)remove_from_login_whitelist— Remove from login whitelist (删除登录白名单)
⚠️ ⛔
isolate_and_kill(隔离查杀)、do_not_isolate_or_kill虽为 API 支持值,但本技能明确不执行隔离/杀毒等高危动作,AI 不得使用。
Update vulnerability handling status:
hcloud HSS ChangeVulStatus --cli-region={region} --project_id={project_id} \
--operate_type={ignore|not_ignore|immediate_repair|manual_repair|verify|add_to_whitelist} \
--data_list.1.vul_id={vul_id} --host_data_list.1.host_id={host_id}
⚠️ 漏洞与主机通过
--data_list.[N].vul_id+--host_data_list.[N].host_id关联传递(没有顶层--vul_id/--host_id参数)。
⚠️ Both ChangeEvent and ChangeVulStatus are mutating operations. Always prompt the user for confirmation before executing.
Parameter Confirmation
| Parameter | Required | Description | Example |
|---|---|---|---|
--cli-region | Yes | Target region | {your-region} |
--project_id | Yes | Project ID (auto-detected if omitted) | Auto from CLI profile |
--host_id | No | Filter by host ID | xxxxxxxx-xxxx-xxxx |
--severity | No | Risk severity filter | critical, high, medium, low |
--type | No | Vulnerability type | linux_vul, windows_vul, web_cms |
--repair_priority | No | Vulnerability repair priority | critical, high, medium, low |
--handle_status | No | Alert handling status filter | handled, unhandled |
--event_class_ids.N | No | Event class ID filter (indexed) | av_1004 (trojan) |
--limit | No | Page size (default 10) | 10 |
--offset | No | Page offset (default 0) | 0 |
--enterprise_project_id | No | Enterprise project filter | 0 for default |
--asset_value | No | Asset importance filter | important, common, test |
Output Format
All commands return JSON by default. For inspection reports, the skill aggregates multiple query results into a structured risk summary:
{
"inspection_time": "2026-08-28T10:00:00Z",
"region": "{region}",
"host_summary": { "total": 10, "protected": 8, "at_risk": 3 },
"vulnerabilities": { "critical": 2, "high": 5, "medium": 12, "low": 8 },
"baselines": { "pass_rate": "85%", "failed_rules": 7 },
"alerts": { "unhandled_trojan": 1, "unhandled_brute_force": 3 },
"risk_score": 72,
"recommendations": ["Fix 2 critical vulnerabilities on host xxx", "Handle 1 unhandled trojan alert"]
}
Reference Documents
references/cli-installation-guide.md— hcloud CLI installation and authenticationreferences/iam-policies.md— Least-privilege IAM policies for HSSreferences/verification-method.md— Verification and testing methodsreferences/dataflow-diagram.md— Data flow diagramreferences/acceptance-criteria.md— Acceptance criteriareferences/hss-event-class-reference.md— HSS event class ID reference
KooCLI Command Format Standard
hcloud HSS ListHostStatus --cli-region={region} --project_id={project_id} [--key=value ...]
| Feature | Description | Example |
|---|---|---|
| Service name | HSS (exact KooCLI service name) | HSS |
| Operation name | PascalCase | ListHostStatus, ShowVulStatics, ChangeEvent |
| Region parameter | --cli-region= | --cli-region={region} |
| Simple parameter | --key=value | --host_id=xxx |
| Indexed parameter | --key.1=value1 | --host_id_list.1=xxx |
Related skills
Read-only query of Huawei Cloud ECS, BMS, IMS, and AS resources via local Python scripts.
Read-only queries against Huawei Cloud resources for inventory, verification, and parameter discovery.
Query Huawei Cloud WAF (Web Application Firewall) attack events, access/protection logs, attack statistics, threat overview and top attack source IPs for daily security inspection and incident troubleshooting. Triggers include: "查询WAF攻击事件", "查询WAF告警", "查看WAF防护日志", "查看WAF访问日志", "WAF攻击统计", "WAF威胁概览", "查询攻击源IP", "waf query", "waf attack events", "waf logs", "waf statistics", "web application firewall", "安全日报", "日常巡检WAF".
Audit Huawei Cloud skills for quality, security, and compliance using a two-check pipeline: skillspector (AI security) and gitleaks (credential leak). Generates structured reports with issue details and fix strategies. Triggers include: "审计技能","技能审计","检查技能质量","扫描技能问题","技能安全审计", "audit skill","check skill quality","scan skills for issues","skill audit", "华为云技能审计","技能合规检查","skill gate","质量门禁","技能检查", "audit huawei cloud skill","verify skill compliance","技能质量检查","跑审计","安全扫描".
Queries Huawei Cloud Cloud Connect (CC) resources via hcloud CLI. Covers cloud connection instances (single + list), bandwidth packages (single + list), inter-region bandwidths (single + list), network instances (single + list), cloud connection routes (single + list), and cross-account authorisations (granted + received). No write operations. Use this skill when the user needs to inspect cross-cloud connectivity topology, check bandwidth package status, review inter-region bandwidth allocation, query network instances attached to a cloud connection, troubleshoot routing in Cloud Connect, or audit cross-account authorisation relationships (who authorised whom). Triggers: 云连接, CC, Cloud Connect, 带宽包, bandwidth package, 域间带宽, inter-region bandwidth, 网络实例, network instance, 路由查询, cloud connection route, 跨云网络, cross-cloud connectivity, 授权, authorisation, 被授权, permission, 跨账号, cross-account.