huawei-cloud-ecs-dsh-deploy

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/deploy_dsh.py

No explicit malware/backdoor behavior is present in the shown code fragment. The script is a high-impact infrastructure automation/orchestration tool that provisions ECS resources and triggers remote deployment via COC/UniAgent, running under a default root execution context. The most concrete security concern in this fragment is sensitive credential exposure (server initial password printed to console and potentially included in notifications). The primary supply-chain/sabotage risk would reside in the imported helper modules and the COC deployment scripts they invoke; those are not visible here, so confidence in malware absence is limited.

Confidence: 42%Severity: 65%
Audit Metadata
Analyzed At
Sep 7, 2026, 08:54 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-ecs-dsh-deploy%2F@da7592141ea465928c4367cf396bf9b340260eadab786572eeff3b3c6655ad5f
Security Audit — socket — huawei-cloud-ecs-dsh-deploy