aws-wechat-article-assets

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core asset-library behavior is coherent, and the remote bundle source appears same-publisher, but importing remote/local `.aws` bundles that can update root `aws.env` credentials and overwrite guidance files is broader than a typical preset manager. Main concern is scope proportionality and trusted-file injection, not confirmed malware or exfiltration.

Confidence: 86%Severity: 59%
Audit Metadata
Analyzed At
Apr 26, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/aiworkskills%2Fwechat-article-skills%2Faws-wechat-article-assets%2F@edb28ce6e22ae967c58f211fdc976b8f2321001e