huawei-cloud-apig-instance-management

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/skill_quality_sdk.py

The code is an explicit cloud telemetry SDK rather than an apparent covert backdoor. Its main security concern is intentional collection and network transmission of function inputs, outputs, errors, and stack traces, combined with use of cloud credentials and a configurable destination. Secret masking is incomplete, and the optional insecure TLS mode can expose credentials and reports to interception. The configurable endpoint also creates a potential exfiltration path if deployment environment variables are attacker-controlled. No clear destructive or covert malware behavior is evident. As supplied, the fragment also has a syntax error due to the unterminated self_check call.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-apig-instance-management%2F@a49d1a7d1ac602b14a96128f724472aac5c8ebd5f89520f3097ce722ede6bd33
Security Audit — socket — huawei-cloud-apig-instance-management