aws-secrets-manager

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
references/asm-exec

No clear in-module indicators of covert malware (no obfuscation/persistence/reverse shell), but the code is a high-impact secret-resolution and command-execution wrapper. It retrieves SecretString values from Secrets Manager (via configurable endpoints) and then injects them into arguments/environment for an arbitrary subprocess. Because endpoints are environment-configurable and tokens may be sent to SMA_ENDPOINT, an attacker who can control environment/inputs can substantially increase risk of secret exfiltration or misuse. Treat as security-sensitive in the supply chain and restrict/validate who can set endpoints and who can influence placeholders/commands.

Confidence: 72%Severity: 73%
Audit Metadata
Analyzed At
Jul 24, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/Mrziadd0%2FAgent-setofskills%2Faws-secrets-manager%2F@9fcbeaae19aff460228ff3634854cf86480392053f5e3491e657381b40bfcda6
Security Audit — socket — aws-secrets-manager