arvancloud-api

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/dns-and-tls.md

The content is operational documentation for ArvanCloud DNS and Let's Encrypt certificate deployment, not apparent malware. The principal security concern is unsafe shell construction in the deployment example: untrusted or compromised deployHooks values can inject commands or cause private keys to be copied to unintended locations. DNS deletion and remote key deployment are powerful but purpose-consistent operations. Configuration values should be strictly validated and shell-escaped, and API keys/private keys should be protected.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 12, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/erfnzdeh%2Farvancloud-agent-skill%2Farvancloud-api%2F@85f0febbaef0b3567207dabe4f0153c154a03c3a
Security Audit — socket — arvancloud-api