aws-skills
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyNo clear standalone supply-chain malware/backdoor indicators are visible in the provided fragment. However, the code includes materially dangerous security properties: (1) an agent configuration that enables high-impact tool capabilities (including 'Bash') and (2) a filesystem-reading tool that runs grep over a path built from an unvalidated, caller-influenced directory value, which is consistent with path traversal and unauthorized file enumeration within mounted volumes. The final agent result is returned to the caller, so tool-discovered file information can be exposed. Because key components are truncated/opaque (sync_config(), query/tool enforcement), this should be treated as a significant security review item rather than confirmed maliciousness.