llm-to-bedrock
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core Bedrock-migration purpose is coherent, and data flows mostly target official AWS tooling, but the skill has a broad operational footprint: arbitrary repo cloning, credential use, repo-local key materialization, git-writing behavior, paid model calls, and mandatory delegation to another skill plus multiple subagents. This looks more like a high-trust orchestration skill than clear malware, but the transitive trust and autonomous rewrite flow make it medium risk.
Confidence: 86%Severity: 61%
Audit Metadata