gcp-to-aws

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/phases/generate/generate-artifacts-ai.md

No clear evidence of intentional malware (data theft, backdoors, exfiltration, or destructive actions) is present in the provided fragment. However, the generated deployment scripts contain a significant supply-chain/tooling integrity risk: both use `eval "$@"` to execute dynamically constructed shell commands when `--execute` is provided, and they interpolate complex templated values (including system prompts/tool lists) without demonstrable escaping/quoting before `eval`. If any of those template inputs can be influenced by an attacker (e.g., compromised design config), this can become command-injection/sabotage on the deployment host. Terraform and the bridge stub appear primarily operational/observability scaffolding.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Sep 12, 2026, 01:42 AM
Package URL
pkg:socket/skills-sh/awslabs%2Fstartups%2Fgcp-to-aws%2F@45f33657890d76c053d7fe3ceb2f2fd534da13c1289fa3c773263933b755d95a
Security Audit — socket — gcp-to-aws