llm-to-bedrock

Warn

Audited by Socket on Oct 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Bedrock migration and access-check capabilities fit the stated purpose, and data flows mainly target local repos plus official AWS endpoints. However, the skill is high-trust and overpowered: it installs/depends on another skill, reads and executes that sibling skill's instructions inline, clones arbitrary repos, performs broad git mutations, and optionally handles third-party API keys alongside AWS credentials. This is not confirmed malware, but the transitive-skill trust chain and wide execution scope make it medium/high risk.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Oct 3, 2026, 01:58 AM
Package URL
pkg:socket/skills-sh/aws%2Fagent-toolkit-for-aws%2Fllm-to-bedrock%2F@a21384aa0bc404a68c3669cb3c78c3361095fb48786a68a0f4de62b158c739af
Security Audit — socket — llm-to-bedrock