aws-well-architected

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but it adds a third-party trust layer: AWS Well-Architected access is routed through Membrane instead of direct AWS tooling. The install source is legitimate npm, not malware-like, yet credential/token handling and API proxying through a non-AWS intermediary make the footprint broader than a typical AWS-only integration.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Faws-well-architected%2F@edb2f4683039ad63dbffd85f1d654ec6a811e2f1d7d491c9d88fd3e490bf297e
Security Audit — socket — aws-well-architected