huawei-cloud-eip-cost-optimizer

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The official SDK dependency path is mostly legitimate and the cloud credential scope is broadly plausible, but the skill is internally inconsistent: it markets itself as read-only while documenting bandwidth changes, tag management, release-oriented workflows, and privileged local jq remediation. Data flows to official Huawei APIs appear coherent, yet webhook/email alerting and shell-level system changes expand scope beyond a narrow reporting skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-eip-cost-optimizer%2F@ba3ef4460a39316170234b71a093706a4dbf7d3d2c7624f6aca0f8ce877ac897
Security Audit — socket — huawei-cloud-eip-cost-optimizer