aws-sdk-java-v2-secrets-manager

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/spring-boot-integration.md

No clear malicious or supply-chain attack behavior is present. The code implements expected AWS Secrets Manager access and credential use. The main security issue is that caller-controlled endpoint values receive secret-derived HTTP headers, enabling potential credential disclosure and SSRF; restrict endpoints to an HTTPS allowlist and avoid forwarding credentials to untrusted destinations. CSRF configuration, incomplete property-source registration, and sample-code compilation inconsistencies also require review.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 14, 2026, 09:10 PM
Package URL
pkg:socket/skills-sh/giuseppe-trisciuoglio%2Fdeveloper-kit%2Faws-sdk-java-v2-secrets-manager%2F@c2de8775e58bda54b826145eb97b24e63fd22b4c888c59cb7ad2422b42546aee
Security Audit — socket — aws-sdk-java-v2-secrets-manager