cloud-weaver-vm-setup

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities are broadly coherent with VM provisioning, and the SSH key/file access is proportionate to that purpose. The main concern is data-flow integrity: it asks the user to supply and store the cloud API endpoint, then sends Locaweb API credentials to that host, while the claimed CloudStack endpoint model does not cleanly match Locaweb’s current public docs. That inconsistency is enough to raise medium risk, but there is no clear evidence of malware, covert exfiltration, or an unverifiable external binary.

Confidence: 84%Severity: 56%
AnomalyLOW
scripts/vm-provision.py

The code is a cloud infrastructure provisioning utility with behavior consistent with its stated purpose. It contains no clear malware, data theft, persistence, reverse shell, or obfuscated payload indicators. The main security risks are unrestricted Internet-facing firewall rules, accepting an arbitrary API endpoint without enforcing HTTPS, possible exposure of infrastructure details in the output file, and the apparent incomplete final main() call. It should be reviewed and corrected before use, particularly the firewall source range and endpoint validation.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 11, 2026, 10:21 PM
Package URL
pkg:socket/skills-sh/fagnerlopes%2Fcloud-weaver%2Fcloud-weaver-vm-setup%2F@1c56672da863348e33a7ee1f81c121e634c0856d7bbb202afe47651f430a4012
Security Audit — socket — cloud-weaver-vm-setup