amazon-bedrock
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core Bedrock/AWS guidance is mostly coherent and uses official AWS endpoints and tooling, but the skill’s footprint extends into higher-risk areas: autonomous payments, caller-supplied Harness overrides, remote skill/MCP/Git sources, and mutable external guidance fetches. This is not confirmed malware or credential harvesting, yet it is a high-risk operational skill that should only be used with strict caller controls, allowlists, and approval around payment and deployment actions.
Confidence: 88%Severity: 74%
Audit Metadata