huawei-cloud-mrs-host-alarm-diagnose

Warn

Audited by Socket on Aug 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/lakewatch_api_client.py

No clear evidence of intentional malware (no reverse shell/persistence/exfiltration code or obfuscation) is present in this fragment. However, it executes a configurable external CryptoAPI binary on non-Windows platforms and provides it sensitive plaintext/ciphertext via stdin, which is a notable supply-chain risk. Additionally, TLS verification can be disabled via configuration, and the download output path is CLI-controlled without strict directory/path constraints. These warrant careful review of the CryptoAPI binary provenance and secure TLS configuration.

Confidence: 62%Severity: 55%
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose and most capabilities align with MRS alarm diagnosis, and there are no clear malware indicators or overtly malicious commands. However, the skill depends on a non-public custom LakeWatch client, stores and uses service credentials from a local config, and routes sensitive cluster/log access through a configurable intermediary endpoint whose official provenance is not established in the provided evidence.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-mrs-host-alarm-diagnose%2F@2c24ca5861bef5f3d399e9ce38a72598893d02865594608fc2247f9279b51bee
Security Audit — socket — huawei-cloud-mrs-host-alarm-diagnose