agentcore-investigation
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalykiro-skill-setup.md
LOWAnomalyLOW
kiro-skill-setup.md
The fragment is legitimate setup documentation for a CloudWatch investigation agent and provides no direct evidence of malware. It does introduce supply-chain and operational security risks: unpinned remote repository content, mutable @latest executable packages, broad shell and filesystem permissions, and access to potentially sensitive AWS telemetry. Pin repository commits and package versions or hashes, review fetched skill and MCP code, use least-privilege AWS credentials, and restrict execute_bash/fs_write where possible.
Confidence: 97%Severity: 55%
Audit Metadata