setting-up-cloudwatch-observability

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/azure-ingestion/custom-telemetry.md

The fragment is legitimate CloudWatch Agent onboarding documentation with significant operational security risks: unpinned curl-to-shell execution, an intentionally documented but overbroad tenant-wide VM trust created by the automated path, potentially disruptive IAM trust replacement, and unauthenticated plaintext OTLP listeners on all interfaces. The text repeatedly warns about these issues and provides safer manual procedures. No direct evidence of malware, credential theft, exfiltration, persistence, or obfuscation appears in the supplied portion. Review and pin the remote scripts, verify their contents and integrity, narrow VM trust with :sub before use, preserve existing IAM trust policies, and restrict OTLP network exposure.

Confidence: 96%Severity: 72%
AnomalyLOW
references/cloudwatch-omni/azure-ingestion/custom-telemetry.md

The fragment is legitimate deployment and security guidance for CloudWatch Agent federation from Azure to AWS. It contains no visible malware or covert data theft. The main risks are executing mutable remote scripts via curl|sh, the VM onboarding script's initially tenant-wide OIDC trust, potentially disruptive shared-role trust-policy updates, and the unauthenticated 0.0.0.0 OTLP example. The explicit warnings and safer manual trust policies reduce the likelihood of intentional malicious behavior, but the installation method should be pinned and verified before production use.

Confidence: 94%Severity: 68%
Audit Metadata
Analyzed At
Sep 22, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/aws%2Fagent-toolkit-for-aws%2Fsetting-up-cloudwatch-observability%2F@12eac10dfc7f7d7eb96e9beaebc5e4eb3b5e451354af9a3b2dbee852b029e45c
Security Audit — socket — setting-up-cloudwatch-observability