huawei-cloud-mrs-host-fault-diagnose

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lakewatch_api_client.py

No clear evidence of intentional malware (no reverse shell/persistence/exfiltration code or obfuscation) is present in this fragment. However, it executes a configurable external CryptoAPI binary on non-Windows platforms and provides it sensitive plaintext/ciphertext via stdin, which is a notable supply-chain risk. Additionally, TLS verification can be disabled via configuration, and the download output path is CLI-controlled without strict directory/path constraints. These warrant careful review of the CryptoAPI binary provenance and secure TLS configuration.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 7, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-mrs-host-fault-diagnose%2F@0e7377dca65b21f4f36be2a8d57c5661d9b7d85cf7c7988deabe461192cf7de3
Security Audit — socket — huawei-cloud-mrs-host-fault-diagnose