aws-cloudformation

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent purpose-strength alignment: it is a guidance-focused wrapper around an external AWS provisioning plugin. However, the footprint raises notable security concerns: reliance on an unverifiable third-party plugin, potential credential handling unknowns, and supply-chain risk. The absence of explicit credential management, per-action consent controls, and provenance verification makes the deployment path potentially unsafe in untrusted contexts. Given these signals, the skill should be classified as SUSPICIOUS with elevated scrutiny for supply-chain integrity and credential handling, rather than clearly benign.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Faws-cloudformation%2F@df657a20dde679ab1bab54d2930212455fa2b0d5