alibabacloud-mtr-network-diagnosis-customer

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/mtr_ecs.py

This module is best characterized as a security-sensitive remote administration tool: it sends base64-encoded Bash scripts to ECS RunCommand for execution, including an explicit arbitrary script runner (--script) and a diagnostic runner that interpolates user-controlled `target`/`tcp_port` directly into shell commands without escaping. While there is no clear evidence of covert malware (no credential theft, persistence, or hidden network exfiltration) in this fragment, the remote execution and injection surfaces make it potentially dangerous if CLI access or inputs are not tightly controlled. Treat as high-impact functionality requiring strict authorization, input validation/escaping, and audit controls.

Confidence: 60%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 06:04 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-mtr-network-diagnosis-customer%2F@983518eb6de57e370b3e5475c6a264c06c3d67aff87f918a68dc9fc6d801cce2
Security Audit — socket — alibabacloud-mtr-network-diagnosis-customer