huawei-cloud-mrs-host-alarm-diagnose
Audited by Socket on Aug 19, 2026
2 alerts found:
Anomalyx2No clear evidence of intentional malware (no reverse shell/persistence/exfiltration code or obfuscation) is present in this fragment. However, it executes a configurable external CryptoAPI binary on non-Windows platforms and provides it sensitive plaintext/ciphertext via stdin, which is a notable supply-chain risk. Additionally, TLS verification can be disabled via configuration, and the download output path is CLI-controlled without strict directory/path constraints. These warrant careful review of the CryptoAPI binary provenance and secure TLS configuration.
SUSPICIOUS. The stated purpose and most capabilities align with MRS alarm diagnosis, and there are no clear malware indicators or overtly malicious commands. However, the skill depends on a non-public custom LakeWatch client, stores and uses service credentials from a local config, and routes sensitive cluster/log access through a configurable intermediary endpoint whose official provenance is not established in the provided evidence.