aws-skills

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Anomaly
AnomalyLOW
cross-service/agent-persistence-patterns.md

No clear standalone supply-chain malware/backdoor indicators are visible in the provided fragment. However, the code includes materially dangerous security properties: (1) an agent configuration that enables high-impact tool capabilities (including 'Bash') and (2) a filesystem-reading tool that runs grep over a path built from an unvalidated, caller-influenced directory value, which is consistent with path traversal and unauthorized file enumeration within mounted volumes. The final agent result is returned to the caller, so tool-discovered file information can be exposed. Because key components are truncated/opaque (sync_config(), query/tool enforcement), this should be treated as a significant security review item rather than confirmed maliciousness.

Confidence: 46%Severity: 67%
Audit Metadata
Analyzed At
Jul 27, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/Overdrive-Consulting%2Fvcskills%2Faws-skills%2F@9671590b414c2f675d971ca02b557b8490725e850decb9698a42d46420ad4a3c
Security Audit — socket — aws-skills