awsclaw-s3

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated S3-management purpose, and there is no direct sign of credential theft or third-party exfiltration. However, the privileged execution layer 'awsclaw' is not verifiable from the provided evidence, and the skill enables impactful cloud mutations using implied AWS credentials without explaining tool provenance or credential routing.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 13, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/necatiarslan%2Fawsclaw%2Fawsclaw-s3%2F@160f01b41dac66937534f8135ef77ba7ef03d3e6
Security Audit — socket — awsclaw-s3