aws-amplify
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose and AWS credential scope fit an Amplify skill, and no clear exfiltration behavior is shown. However, the MCP install reference is doc-inconsistent: it uses an unpinned `uvx` package name that could not be verified against AWS's documented MCP packages, creating meaningful supply-chain risk even if the broader workflow is legitimate.
Confidence: 80%Severity: 62%
Audit Metadata