huawei-cloud-flexus-l-server-hermes-deployment

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and official Huawei endpoints are broadly coherent, and the install source appears same-org legitimate. Risk is elevated because the actual scripts are missing, the skill forwards multiple sensitive credentials, examples contradict the env-only secret guidance by using CLI flags, and it performs autonomous cloud and remote-execution actions with real-world impact.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-flexus-l-server-hermes-deployment%2F@fe2d62be0033ea71ac2b02d1ad63c941ac2ba0c345615e45e3954341c8822ee6
Security Audit — socket — huawei-cloud-flexus-l-server-hermes-deployment