alibabacloud-website-malware-check

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/multi_ua_probe.py

No direct indicators of embedded malware (no obfuscated payloads, no persistence, no local data theft, and no execution primitives). The primary security concerns are operational/defensive: redirects are followed without re-applying the initial public-IP restrictions to redirect targets (redirect-based SSRF-like risk), and TLS verification is intentionally downgraded on SSLError (verify=False). Treat this as a network-probing tool and consider tightening redirect destination validation and TLS handling if used in untrusted environments.

Confidence: 72%Severity: 52%
Audit Metadata
Analyzed At
Aug 26, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-website-malware-check%2F@ed43a048b88b67da9da32095c83ccde6b2e43948e6eb959d01dc4ec96ad8b58e
Security Audit — socket — alibabacloud-website-malware-check