alibabacloud-lingjun-node-ops
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
AnomalyAnomalyreferences/mutating-schemas/run-command.yaml
LOWAnomalyLOW
references/mutating-schemas/run-command.yaml
This YAML is not malicious code by itself; it is a schema/config that defines a high-privilege mutating capability (run-command) accepting arbitrary user-provided command content (optionally Base64) and defaulting to root execution context (/root, username root). The main security risk is capability misuse or insufficient backend authorization/validation/sandboxing/allowlisting in the executor that consumes these fields. Stop-invocation is a standard operational control with minimal exposure. No direct evidence of malware, credential theft, persistence, or exfiltration exists within this fragment.
Confidence: 65%Severity: 62%
Audit Metadata