aws-amplify

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated AWS Amplify purpose is coherent, and the likely data flow is to AWS-owned services, but it executes an external MCP package with mutable @latest and the specific package name could not be strongly verified against official AWS naming patterns. This is a medium supply-chain and credential-forwarding risk, not confirmed malware.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Jul 27, 2026, 03:30 AM
Package URL
pkg:socket/skills-sh/whchoi98%2Faws-skills-for-claude-code%2Faws-amplify%2F@5961692b87f8dfda0a67b175a6c571dce78b47290b0a727017267611835281ec
Security Audit — socket — aws-amplify