llm-to-bedrock

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Bedrock-migration purpose is coherent, and data flows mostly target official AWS tooling, but the skill has a broad operational footprint: arbitrary repo cloning, credential use, repo-local key materialization, git-writing behavior, paid model calls, and mandatory delegation to another skill plus multiple subagents. This looks more like a high-trust orchestration skill than clear malware, but the transitive trust and autonomous rewrite flow make it medium risk.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:15 PM
Package URL
pkg:socket/skills-sh/awslabs%2Fstartups%2Fllm-to-bedrock%2F@800cfa6d9edc53e894db1cc12cbda64d4becc3323b45e962c519d5fe7a799052
Security Audit — socket — llm-to-bedrock