huawei-cloud-ecs-passwordless-login

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses official Huawei services, so it does not look like credential-harvesting malware. However, it performs high-impact cloud and SSH actions, disables SSH trust checks, appends persistent local SSH config, and deliberately preserves root access after key cleanup via ControlMaster, making it a high-risk infrastructure automation skill rather than a low-risk helper.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-ecs-passwordless-login%2F@927178117a1a5c649b82c37ab7a927128b0f6480fa7636670f528465f274ea39
Security Audit — socket — huawei-cloud-ecs-passwordless-login