aws-amplify
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated AWS Amplify purpose is coherent, and the likely data flow is to AWS-owned services, but it executes an external MCP package with mutable @latest and the specific package name could not be strongly verified against official AWS naming patterns. This is a medium supply-chain and credential-forwarding risk, not confirmed malware.
Confidence: 81%Severity: 56%
Audit Metadata