huawei-cloud-cce-kubernetes-event-analyzer

Fail

Audited by Snyk on Jul 28, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.90). This is a GitHub release tarball from a personal/unknown account that delivers a native executable plugin (to be extracted and installed), which matches high-risk indicators for untrusted executable distribution and should be treated as suspicious until verified.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). Current and LTS workflows ingest Kubernetes Event fields (e.g., message, reason, LTS content parsed as JSON) retrieved at runtime via kubectl get events ... -o json / hcloud LTS ListLogs, which are outsider-authored system-generated text from the user’s cluster and logs.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 28, 2026, 08:09 AM
Issues
2
Security Audit — snyk — huawei-cloud-cce-kubernetes-event-analyzer