alibabacloud-lingjun-node-ops

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mutating-schemas/run-command.yaml

This YAML is not malicious code by itself; it is a schema/config that defines a high-privilege mutating capability (run-command) accepting arbitrary user-provided command content (optionally Base64) and defaulting to root execution context (/root, username root). The main security risk is capability misuse or insufficient backend authorization/validation/sandboxing/allowlisting in the executor that consumes these fields. Stop-invocation is a standard operational control with minimal exposure. No direct evidence of malware, credential theft, persistence, or exfiltration exists within this fragment.

Confidence: 65%Severity: 62%
Audit Metadata
Analyzed At
Sep 8, 2026, 02:02 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-lingjun-node-ops%2F@6c69bf62209fc7dba0bd8ef3bf8674ffb41dc13edd1716f9bd9d440d635e0f16
Security Audit — socket — alibabacloud-lingjun-node-ops