bedrock-agentcore-evaluations

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill/documentation appears coherent and consistent with its stated purpose (creating and running evaluator checks for Bedrock AgentCore agents, including LLM-as-Judge evaluators, CloudWatch integration, and dashboards). There is no evidence of obfuscation, malicious backdoors, or credential harvesting. The main security concerns are operational: evaluation content and assistant responses are routed to model inference endpoints (Anthropic via Bedrock) and CloudWatch logs, which can expose PII/PHI if not redacted or access‑controlled. Teams should ensure appropriate IAM scoping, logging retention/access policies, and avoid sending sensitive data to evaluators unless permitted. Overall I find no malicious behavior in the provided content.

Confidence: 80%Severity: 25%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:11 PM
Package URL
pkg:socket/skills-sh/adaptationio%2Fskrillz%2Fbedrock-agentcore-evaluations%2F@c57c7d36a58ac9f2e0695ac5122a6e60313c8a3d