aws-observability
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalyreferences/appsignals-guides/ec2-java.md
LOWAnomalyLOW
references/appsignals-guides/ec2-java.md
No direct indicators of overt malware are present in this snippet; however, it performs a high-impact supply-chain operation by downloading a Java agent JAR from a non-pinned “latest” GitHub release and immediately loading it into the application JVM via JAVA_TOOL_OPTIONS without showing integrity verification. This should be treated as a meaningful supply-chain risk. Additional operational risk exists if template variables used in user-data are not strictly controlled, and the example use of --network host warrants firewall/security-group review to limit exposure of OTLP/agent-related ports.
Confidence: 66%Severity: 57%
Audit Metadata