huawei-cloud-waf-aad-rule-management

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/skill_quality_sdk.py

The code is a telemetry/reporting SDK with legitimate-looking Huawei Cloud integration. It is not clearly malware, but it introduces a meaningful data-privacy and credential-exposure risk because it uploads execution data and unmasked stack traces, reads cloud credentials, permits an environment-controlled destination, and supports disabling TLS verification. The fragment also appears syntactically incomplete at the final self_check( call if copied exactly.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/huaweicloud%2Fhuaweicloud-skills%2Fhuawei-cloud-waf-aad-rule-management%2F@51b4529b51de4ce79a292a1b9c6762a14c267f98953127c82e9bc0c116820c0a
Security Audit — socket — huawei-cloud-waf-aad-rule-management