huawei-cloud-cce-cluster-management

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated Huawei CCE management purpose, and most data flows appear to target official Huawei services. Main risks are supply-chain trust from curl-to-bash installation, credential forwarding into external CLI/plugin tooling, and transitive installation of another skill for kubectl-cce. This looks more like a powerful infrastructure-admin skill with meaningful operational and credential-handling risk than confirmed malware.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Aug 27, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-cce-cluster-management%2F@77eb49eaadfff6247f11eb770efda5dc9f3489b5b38bb6636f3862938b1ef5f0
Security Audit — socket — huawei-cloud-cce-cluster-management