huawei-cloud-flexus-l-server-hermes-deployment
Warn
Audited by Socket on Jun 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and official Huawei endpoints are broadly coherent, and the install source appears same-org legitimate. Risk is elevated because the actual scripts are missing, the skill forwards multiple sensitive credentials, examples contradict the env-only secret guidance by using CLI flags, and it performs autonomous cloud and remote-execution actions with real-world impact.
Confidence: 100%Severity: 60%
Audit Metadata