alibabacloud-elasticsearch-instance-manage

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose and use official Alibaba tooling, so it is not malware-like. The main risk is the mandatory enablement of automatic plugin installation: it downloads and runs additional executables that inherit cloud credentials, increasing supply-chain and credential-forwarding risk. Because the skill also authorizes impactful cloud actions like instance creation and restart, overall risk is medium rather than low.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 31, 2026, 10:33 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-elasticsearch-instance-manage%2F@5f6b4f1aa3b51149d69add272529857d4fa78c75