bedrock-agentcore-evaluations
Audited by Socket on Feb 15, 2026
1 alert found:
MalwareThis skill/documentation appears coherent and consistent with its stated purpose (creating and running evaluator checks for Bedrock AgentCore agents, including LLM-as-Judge evaluators, CloudWatch integration, and dashboards). There is no evidence of obfuscation, malicious backdoors, or credential harvesting. The main security concerns are operational: evaluation content and assistant responses are routed to model inference endpoints (Anthropic via Bedrock) and CloudWatch logs, which can expose PII/PHI if not redacted or access‑controlled. Teams should ensure appropriate IAM scoping, logging retention/access policies, and avoid sending sensitive data to evaluators unless permitted. Overall I find no malicious behavior in the provided content.