aws-wechat-article-assets
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core asset-library behavior is coherent, and the remote bundle source appears same-publisher, but importing remote/local `.aws` bundles that can update root `aws.env` credentials and overwrite guidance files is broader than a typical preset manager. Main concern is scope proportionality and trusted-file injection, not confirmed malware or exfiltration.
Confidence: 86%Severity: 59%
Audit Metadata