llm-to-bedrock
Warn
Audited by Socket on Oct 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core Bedrock migration and access-check capabilities fit the stated purpose, and data flows mainly target local repos plus official AWS endpoints. However, the skill is high-trust and overpowered: it installs/depends on another skill, reads and executes that sibling skill's instructions inline, clones arbitrary repos, performs broad git mutations, and optionally handles third-party API keys alongside AWS credentials. This is not confirmed malware, but the transitive-skill trust chain and wide execution scope make it medium/high risk.
Confidence: 87%Severity: 71%
Audit Metadata