aws-ses-inbound

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: setting up SES inbound with SNS delivery to a webhook. It uses official AWS tooling (awscli) and standard SES/SNS resources. The primary risks arise from handling of inbound data to an external webhook and from credential management there is limited detail on least-privilege scoping and verification hardening. Overall, the pattern is benign but warrants careful exposure controls, explicit SNS signature verification, and explicit webhook authentication/validation to reduce data exposure and abuse risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 02:59 AM
Package URL
pkg:socket/skills-sh/different-ai%2Fzero-finance%2Faws-ses-inbound%2F@c22aadbb4880eaa115a7dc6d6113045dbe65969f