stack-evaluation
Audited by Socket on Apr 1, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill's purpose is coherent, but its install instructions are not: it points to unofficial `uvx` package names instead of AWS Labs' documented MCP servers. Because those packages are executed on demand and may receive AWS credentials, the supply-chain and credential-forwarding risk is high relative to a cost-estimation skill.
SUSPICIOUS. The core Google CLI and Billing API flows are legitimate and proportionate for GCP cost estimation, but the skill also instructs installation of unverified third-party MCP packages via `uvx`, including one with a strongly inconsistent PyPI description. That unverifiable install path is not necessary to the stated purpose and materially raises supply-chain risk, even though the documented Google API data flow itself is benign.