amazon-bedrock

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Bedrock/AWS guidance is mostly coherent and uses official AWS endpoints and tooling, but the skill’s footprint extends into higher-risk areas: autonomous payments, caller-supplied Harness overrides, remote skill/MCP/Git sources, and mutable external guidance fetches. This is not confirmed malware or credential harvesting, yet it is a high-risk operational skill that should only be used with strict caller controls, allowlists, and approval around payment and deployment actions.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Famazon-bedrock%2F@db64c5a23e2060f3796f79ef1652c7f448e2a3f1ad10cf1967917e38aeca075d
Security Audit — socket — amazon-bedrock