huawei-cloud-ecs-passwordless-login
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses official Huawei services, so it does not look like credential-harvesting malware. However, it performs high-impact cloud and SSH actions, disables SSH trust checks, appends persistent local SSH config, and deliberately preserves root access after key cleanup via ControlMaster, making it a high-risk infrastructure automation skill rather than a low-risk helper.
Confidence: 89%Severity: 68%
Audit Metadata