linux-cloud-init
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalyreferences/user-data-reference.md
LOWAnomalyLOW
references/user-data-reference.md
No explicit malicious payload is visible in the fragment, but it contains a high-impact supply-chain execution pattern: it can clone external code during first boot and run scripts from that unpinned, unverified source. It also configures passwordless sudo for the admin user, which significantly amplifies the consequences of any compromise. Additional network exposure risks exist in the database variant due to broad PostgreSQL listening and access rules. Treat the git-clone-and-execute step and NOPASSWD configuration as primary issues requiring hardening (pinning, signature/checksums, and least-privilege).
Confidence: 60%Severity: 65%
Audit Metadata