cloud-architect
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core AWS functionality is largely coherent and uses official AWS Labs/AWS-owned endpoints, which is a strong benign signal. Risk comes from combining action-capable AWS API tooling with external content retrieval and a third-party Upstash MCP that is not necessary for the core AWS mission, creating medium supply-chain and prompt-injection exposure rather than clear malicious intent.
Confidence: 86%Severity: 58%
Audit Metadata