stack-evaluation

Warn

Audited by Socket on Apr 1, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
cost-aws/SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but its install instructions are not: it points to unofficial `uvx` package names instead of AWS Labs' documented MCP servers. Because those packages are executed on demand and may receive AWS credentials, the supply-chain and credential-forwarding risk is high relative to a cost-estimation skill.

Confidence: 93%Severity: 86%
SecurityMEDIUM
cost-gcp/SKILL.md

SUSPICIOUS. The core Google CLI and Billing API flows are legitimate and proportionate for GCP cost estimation, but the skill also instructs installation of unverified third-party MCP packages via `uvx`, including one with a strongly inconsistent PyPI description. That unverifiable install path is not necessary to the stated purpose and materially raises supply-chain risk, even though the documented Google API data flow itself is benign.

Confidence: 94%Severity: 84%
Audit Metadata
Analyzed At
Apr 1, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/bnayae%2Fbnaya-agent-skills%2Fstack-evaluation%2F@952610ad0d9a04898f0b3e30863b2b896283cea2
Security Audit — socket — stack-evaluation