over-permissioned

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is simple file organization, but the skill asks for sensitive AWS/SSH-related file access, broad shell permissions, and sudo-level recursive execution. The capability and credential scope are not proportionate to a file organizer, and the claimed S3 use leaves data flow unclear.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Sep 1, 2026, 11:06 AM
Package URL
pkg:socket/skills-sh/aws-samples%2Fsample-agent-skill-eval%2Fover-permissioned%2F@5e391802228d73f0ac52c27cfd1149507d37ef77262f7ad8c03fb1398df6ff98
Security Audit — socket — over-permissioned