huawei-cloud-cce-kubernetes-event-analyzer
Fail
Audited by Snyk on Jul 28, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). This is a GitHub release tarball from a personal/unknown account that delivers a native executable plugin (to be extracted and installed), which matches high-risk indicators for untrusted executable distribution and should be treated as suspicious until verified.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Current and LTS workflows ingest Kubernetes Event fields (e.g.,
message,reason, LTScontentparsed as JSON) retrieved at runtime viakubectl get events ... -o json/hcloud LTS ListLogs, which are outsider-authored system-generated text from the user’s cluster and logs.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata