Security

huawei-cloud-network-query

Try it

Read-only queries against Huawei Cloud resources for inventory, verification, and parameter discovery.

What it does

A read-only query skill that retrieves Huawei Cloud resources via local Python scripts wrapping the Huawei Cloud Python SDK. It surfaces resource lists, individual resource details, available specifications, images, disk types, and key identifiers and dependency relationships. Each script is paired with a usage guide under references/<service>/guide.md, and all execution goes through `skill action=exec` — hcloud, openstack, curl, or direct API calls are not used. The skill does not create, modify, or delete resources and never fabricates fields that are not in the actual API response.

When to use it

  • Inventory existing Huawei Cloud resources in a specific region
  • Look up available specifications, images, or disk types for planning
  • Verify resource attributes before Terraform or other IaC runs
  • Collect IDs, names, and dependency links for handoff to other tooling

The skill document

Huawei Cloud Resource Query

⚠️ Execution Method (Must Read): This skill executes queries via local Python scripts. Using hcloud, openstack or other CLI tools or direct API calls is prohibited.

  • Query scripts are located under the skill directory scripts// (e.g., scripts/as/list_scaling_groups.py)
  • All scripts and environment check scripts are inside the skill package. You must use skill action=exec to execute them. Do not run them directly in a shell.
  • For specific script paths and parameters, refer to references//guide.md
  • Do not attempt hcloud, openstack, curl IAM or other CLI/API methods. This skill does not depend on those tools.
  • All paths are relative to the skill directory, which is the directory where this SKILL.md is located.

Overview

This skill is an independent read-only query skill that queries Huawei Cloud resources, available specifications, and existing resource information by calling the Huawei Cloud Python SDK via local Python scripts.

This skill is applicable to the following scenarios:

  1. Query available cloud resource specifications in a specific region
  2. Query which images are available for a certain operating system
  3. Query cloud disk types and existing cloud disk information
  4. Query existing resources and their key attributes
  5. Query resources that were not created through Terraform or other IaC tools
  6. Prepare real parameters for automated configuration, resource verification, or environment inventory
  7. Obtain reusable information such as resource IDs, names, specifications, images, networks, and disks

This skill is NOT responsible for:

  1. Creating resources
  2. Modifying resources
  3. Deleting resources
  4. Guessing or fabricating information that has not been queried

Capability Scope

This skill provides query capabilities through categorized scripts in the scripts directory, and usage instructions through categorized guides in the references directory. The capabilities provided by this skill include:

  1. Query resource lists
  2. Query individual resource details
  3. Query selection information such as available specifications, images, and disk types
  4. Query key identifiers and dependency relationships of existing resources

Usage Principles

Important: Script paths executed within this skill are all relative paths under the skill directory, which is the directory where this SKILL.md is located.

  1. This skill only performs queries; it does not perform any write operations
  2. Prioritize information explicitly specified by the user, such as region, project, AZ, resource name, resource ID, etc.
  3. Query results must be based on actual API responses; do not infer from experience
  4. Returned results should prioritize retaining key fields for subsequent reuse
  5. When the result set is large, narrow the scope first by conditions such as region, name, id, status, tag, etc.
  6. If there is no corresponding script or guide for the current resource type, clearly state that it is not supported; do not return unreliable results
  7. If the user does not provide necessary scope information and there are no default values in the environment, confirm with the user before executing the query
  8. Execute directly according to guide.md; do not view the script contents in the scripts directory
  9. Cache output when it is large
  10. You must run -h to view usage before executing each script
  11. Do not make up script names. Execute according to the script names in guide.md. If a script name is not in guide.md, it means it is not supported

Prerequisites

You must run the environment check script first to complete environment validation and dependency installation in one step:

  • Linux / macOS: skill action=exec: bash skill://scripts/check_env.sh
  • Windows: skill action=exec: powershell -ExecutionPolicy Bypass -File skill://scripts/check_env.ps1

Windows Note: Do not use && to concatenate commands (PowerShell 5.x does not support it). Use semicolons if you need to change directories first.

The script will check in order: Python >= 3.6 → Install dependencies → Validate SDK → Validate credentials → Validate service availability. If the environment check fails, fix the issues before continuing with other scripts.

Environment Variables:

VariableRequiredDescription
HW_ACCESS_KEYYesHuawei Cloud AK
HW_SECRET_KEYYesHuawei Cloud SK
HW_REGION_NAMENoDefault cn-north-4
HW_PROJECT_IDNoProject ID (automatically obtained via IAM API when not set)
HW_SECURITY_TOKENNoRequired when using temporary AK/SK

Do not output the values of the above environment variables. For additional parameters required by other resource scripts (availability zone, enterprise project, etc.), see the corresponding guide.md.


Execution Flow

When this skill is invoked, you must follow these steps. Do not wait for the user to prompt again:

Step 1: Environment Preparation

Run the environment check script to ensure dependencies are installed and credentials are configured:

  • Linux / macOS: skill action=exec: bash skill://scripts/check_env.sh
  • Windows: skill action=exec: powershell -ExecutionPolicy Bypass -File skill://scripts/check_env.ps1

If the environment check fails, fix the issues as prompted and re-run until it passes.

Step 2: Identify and Execute Query Scripts

  1. Based on the user's query intent, read references//guide.md to determine the script path and parameters to execute
  2. First run -h to view the script usage:
    • Linux / macOS: skill action=exec: skill://.venv/bin/python3 skill://scripts//.py -h
    • Windows: skill action=exec: skill://.venv/Scripts/python3.exe skill://scripts//.py -h
  3. Assemble parameters based on user needs and execute the script:
    • Linux / macOS: skill action=exec: skill://.venv/bin/python3 skill://scripts//.py
    • Windows: skill action=exec: skill://.venv/Scripts/python3.exe skill://scripts//.py
  4. Format the results and return them to the user

Important:

  • All scripts and environment check scripts are inside the skill package. You must use skill action=exec to execute them. Do not run them directly in a shell.
  • The venv is automatically created by the check_env script. On Linux/macOS, Python is located at .venv/bin/python3; on Windows, it is at .venv/Scripts/python3.exe
  • Do not execute scripts directly with python3
  • Do not read the script source code in the scripts directory; just follow the instructions in guide.md
  • Cache results when the output is large
  • The --project_id parameter is optional; when not provided, it is automatically obtained via IAM API based on the region

Directory Structure

The directory conventions are as follows (all paths are relative to the skill directory):

  1. scripts// contains the corresponding Python query scripts. There is no need to read script contents; just execute the scripts according to the instructions in guide.md
  2. references//guide.md contains the usage guide for the corresponding resource
  3. Each script is responsible for a single, clear query action
  4. Each resource category must maintain at least one guide.md to document script capabilities, parameters, and usage

Parameter Confirmation

Before executing a query script, confirm the following parameters:

ParameterRequiredDescription
regionYesHuawei Cloud region, e.g., cn-north-4
--project_idNoProject ID; automatically obtained when not provided
--availability_zoneNoAvailability zone; required for some resource queries

For script-specific parameters, see references//guide.md.


Output Format

Query results are output in JSON format and include the following common fields:

  • total: Total number of matched resources
  • items: Resource list, where each resource contains key fields such as id, name, status, etc.
  • Specific fields vary by resource type; see each guide.md for details

Verification Method

  1. Run the environment check script to confirm dependencies and credentials are available
  2. Use the -h parameter to view script usage and confirm parameters are correct
  3. Execute queries on known resources and compare with console data to verify result accuracy
  4. Check whether the returned total count is reasonable

Best Practices

  1. Narrow the query scope first (specify region, availability zone, etc.) to avoid returning too much data
  2. Use --help to view the complete list of parameters supported by a script
  3. Cache query results locally when they are large to avoid repeated requests
  4. When multiple resource information is needed, query in dependency order (e.g., query VPC first, then subnets)
  5. When script execution fails, check environment variables and network connectivity first

Reference Documentation

  • Usage guides for each service query script: references//guide.md

Notes

  1. This skill only provides read-only query capabilities; it does not perform any write operations
  2. Do not output the values of environment variables such as HW_ACCESS_KEY and HW_SECRET_KEY
  3. All scripts must be executed via skill action=exec; do not run them directly in a shell
  4. Do not guess script names; execute strictly according to the names in guide.md
  5. You must run the environment check script before querying
  6. When using temporary AK/SK, you need to set HW_SECURITY_TOKEN

Questions people ask

Does this skill create or modify resources?
No. It is strictly read-only and will not create, modify, or delete any Huawei Cloud resource.
How are queries executed?
Through `skill action=exec` calling local Python scripts under scripts/<service>/, paired with references/<service>/guide.md. It does not use hcloud, openstack, curl, or direct API calls.
What credentials and environment setup are needed?
HW_ACCESS_KEY and HW_SECRET_KEY are required. HW_REGION_NAME (default cn-north-4), HW_PROJECT_ID, and HW_SECURITY_TOKEN are optional per the docs. The check_env script under the skill must pass before queries run.

Related skills

Lists Huawei Cloud EIP (Elastic IP, 弹性公网IP) resources — enumerates all EIPs in a region with public IP address, EIP ID, status, bandwidth, associated instance and creation time, using the KooCLI `hcloud EIP ListPublicips` command (primary) or the huaweicloudsdkeip Python SDK (fallback). Provides read-only EIP inventory for network resource auditing, cost review and resource discovery. Use this skill whenever the user mentions EIP list query. Triggers include: list EIPs, EIP list, query EIP, enumerate EIPs, show EIPs, elastic IP list, public IP inventory, 查询弹性公网IP, EIP列表, 弹性公网IP列表, 查看EIP, 列出EIP, 获取EIP列表, 查询EIP, 查询公网IP.

Read-only query of Huawei Cloud ECS, BMS, IMS, and AS resources via local Python scripts.

by huaweicloud-skills-team2 installs

Query the list of Huawei Cloud public NAT gateways (公网NAT网关) under the current tenant / project, focused on the NAT gateway NAME list. Returns each gateway's name, id, status, spec, router (VPC) id, internal network id and created time. Supports filtering by name, id, status, spec, enterprise project id and pagination via limit/marker. Uses the KooCLI command `hcloud NAT ListNatGateways --cli-region={region}` (primary) against the v2 API, or the huaweicloudsdknat Python SDK (fallback). Read-only — never creates, modifies or deletes any NAT gateway. Use this skill whenever the user wants to list/inspect the public NAT gateways of the tenant or query the NAT gateway name list, e.g. for NAT gateway inventory, daily inspection, or cost review. Triggers include: "list NAT gateways", "NAT gateway list", "query NAT gateway names", "公网NAT网关列表", "查询公网NAT网关", "NAT网关列表", "NAT网关名称", "list nat", "nat list", "how many NAT gateways", "NAT inventory".

Queries Huawei Cloud monitoring and enterprise project resources (CES/EPS). Covers alarm rules, alarm histories, alarm templates, dashboards, notification ma...

by huaweicloud-skills-team1 installs

Queries Huawei Cloud Cloud Connect (CC) resources via hcloud CLI. Covers cloud connection instances (single + list), bandwidth packages (single + list), inter-region bandwidths (single + list), network instances (single + list), cloud connection routes (single + list), and cross-account authorisations (granted + received). No write operations. Use this skill when the user needs to inspect cross-cloud connectivity topology, check bandwidth package status, review inter-region bandwidth allocation, query network instances attached to a cloud connection, troubleshoot routing in Cloud Connect, or audit cross-account authorisation relationships (who authorised whom). Triggers: 云连接, CC, Cloud Connect, 带宽包, bandwidth package, 域间带宽, inter-region bandwidth, 网络实例, network instance, 路由查询, cloud connection route, 跨云网络, cross-cloud connectivity, 授权, authorisation, 被授权, permission, 跨账号, cross-account.

Queries Huawei Cloud ECS (Elastic Cloud Server) resources in read-only mode. Covers ECS instances, flavors, keypairs, quotas, server groups, block devices, NICs, VNC console, launch templates, recycle bin, scheduled events, and tags. No write operations. Use this skill when the user needs to query ECS instance details, list flavors, check server status, view block devices, or inspect ECS resource attributes. Triggers include: 查询ECS, ECS实例查询, 云服务器查询, 弹性云服务器, ECS规格, ECS配额, 云服务器列表, ECS详情, query ECS, list ECS servers, show server details, ECS flavors, ECS quotas, ECS keypairs, server groups, block devices, ECS inventory, cloud server list, ecs list, ecs query, ecs show.

More from huaweicloud-skills-team

Browse all skills

Manage Huawei Ascend NPUs with natural language commands that translate to npu-smi, locally or over SSH.

by huaweicloud-skills-team7 installs

Deploy and test LLM, VL, Embedding, and Rerank models on Huawei Cloud Ascend 910B DevServer with single- or dual-node topologies.

by huaweicloud-skills-team7 installs

Query Huawei Cloud IAM resources (users, groups, policies, agencies, AK/SK, MFA, security settings) read-only via local Python SDK.

by huaweicloud-skills-team6 installs

Manage Huawei Cloud Flexus L instances from chat: list, inspect, start, stop, reboot, reconfigure, and check traffic.

by huaweicloud-skills-team6 installs