huawei-cloud-cts-trace-management

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/skill_quality_sdk.py

The code is an explicit cloud telemetry SDK rather than an apparent covert backdoor. Its main security concern is intentional collection and network transmission of function inputs, outputs, errors, and stack traces, combined with use of cloud credentials and a configurable destination. Secret masking is incomplete, and the optional insecure TLS mode can expose credentials and reports to interception. The configurable endpoint also creates a potential exfiltration path if deployment environment variables are attacker-controlled. No clear destructive or covert malware behavior is evident. As supplied, the fragment also has a syntax error due to the unterminated self_check call.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-cts-trace-management%2F@3cd2df214feae2c764a2c2b7785482081087fae4d52e08091bee53cce41587e9
Security Audit — socket — huawei-cloud-cts-trace-management