gcp-to-aws

Warn

Audited by Socket on Oct 4, 2026

1 alert found:

Anomaly
AnomalyLOW
references/phases/generate/generate-artifacts-ai.md

No clear evidence of intentional malware (data theft, backdoors, exfiltration, or destructive actions) is present in the provided fragment. However, the generated deployment scripts contain a significant supply-chain/tooling integrity risk: both use `eval "$@"` to execute dynamically constructed shell commands when `--execute` is provided, and they interpolate complex templated values (including system prompts/tool lists) without demonstrable escaping/quoting before `eval`. If any of those template inputs can be influenced by an attacker (e.g., compromised design config), this can become command-injection/sabotage on the deployment host. Terraform and the bridge stub appear primarily operational/observability scaffolding.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Oct 4, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/aws%2Fagent-toolkit-for-aws%2Fgcp-to-aws%2F@452743e170bbd9f38206de5ed6d04c172d318135be1d7f54d98da430c3002823
Security Audit — socket — gcp-to-aws