terraform-aws-annotated-blueprint

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill description is aligned with a legitimate goal of generating annotated Terraform templates using provider schemas and AWS docs via MCP servers. However, the footprint introduces notable supply-chain and execution risks: it relies on external binaries and MCP services (download-execute patterns), permits transitive tool installation, and creates data flows to third-party endpoints for knowledge and schema data. While not inherently malicious, the combination of download-execute patterns, external service dependencies, and potential credential exposure surfaces warrants a cautious stance. Recommend rigorous controls: pin/attest MCP server sources, require explicit user approval before external binary execution, enforce authenticated/attested endpoints, and sandbox execution to mitigate supply-chain risk. Overall risk score: moderate-high with actionable mitigations required.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/donngi%2Fagent-skills%2Fterraform-aws-annotated-blueprint%2F@844147fb68dd99868dfc4100ea5d786451b95d38