hyperpod-issue-report

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/hyperpod_issue_report.py

The code is a HyperPod diagnostic collector with extensive privileged data collection and remote command execution through AWS SSM. Its behavior is broadly consistent with the stated troubleshooting purpose. The main security concerns are potential exposure of sensitive log/configuration data to the configured S3 bucket, execution under node permissions, runtime execution of an externally downloaded but hash-pinned script, and a local S3 download path traversal weakness caused by unsanitized object keys. No clear malicious payload, credential theft, persistence, reverse shell, cryptomining, or unrelated exfiltration behavior is evident. The provided fragment also contains syntax errors that require correction before execution.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/awslabs%2Fagent-plugins%2Fhyperpod-issue-report%2F@d1342a10b0e80ba97684069bca4c1d729f8d5357b3e309641d3e45a41befc4f9
Security Audit — socket — hyperpod-issue-report