huawei-cloud-optv-evolve-management

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
references/iam-agency.md

The fragment is operational IAM documentation for granting an OptVerse service broad, persistent access to OBS resources. It shows no direct malware or obfuscated executable behavior, but the `FOREVER` trust relationship, `iam:agencies:assume`, and broad bucket/object administration permissions create a significant cloud security risk. The trust target and required scope should be independently verified, and least-privilege, resource restrictions, temporary duration, and review/approval controls should be considered.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Sep 10, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-optv-evolve-management%2F@597fe6608e2b5ec489c0f4d75739385965cecb281ef0b24ff8addc68de80a0bd
Security Audit — socket — huawei-cloud-optv-evolve-management