aws-observability

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/appsignals-guides/ec2-java.md

No direct indicators of overt malware are present in this snippet; however, it performs a high-impact supply-chain operation by downloading a Java agent JAR from a non-pinned “latest” GitHub release and immediately loading it into the application JVM via JAVA_TOOL_OPTIONS without showing integrity verification. This should be treated as a meaningful supply-chain risk. Additional operational risk exists if template variables used in user-data are not strictly controlled, and the example use of --network host warrants firewall/security-group review to limit exposure of OTLP/agent-related ports.

Confidence: 66%Severity: 57%
Audit Metadata
Analyzed At
Jul 24, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/Mrziadd0%2FAgent-setofskills%2Faws-observability%2F@ffb37d3460fb2b554d8cf67329c55ead8da4f23690c7e93bbf0d64d80f8ca665
Security Audit — socket — aws-observability