huawei-cloud-computing-query

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose and credential scope are broadly coherent for a read-only Huawei Cloud query skill, and the expected data flow appears to target official Huawei APIs. However, the skill forces execution of opaque bundled shell/PowerShell and Python scripts, discourages source inspection, and does not disclose exact dependency installation behavior or versions; this creates medium supply-chain and credential-handling risk rather than clear malicious intent.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Jun 26, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-computing-query%2F@fb943b251d65166356e2780c484aa15b178a4f09509d92206a44bceab7ecd0c2
Security Audit — socket — huawei-cloud-computing-query