cloudformation-template-creator

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct signs of embedded malware or obfuscation in the provided manifest. The main security concern is operational: the combination of Read/Write/Edit with unrestricted Bash(aws:*) allows high-impact AWS operations using whatever credentials the runtime exposes. Recommend reducing privilege scope (limit allowed aws actions), enforce confirmation/dry-run before destructive commands, avoid persisting secrets in generated artifacts/logs, and document least-privilege IAM requirements. Treat as an operationally risky component if run with broad credentials.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:40 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcloudformation-template-creator%2F@bb6cf479a47d5ad74fb1ae546cef68c03289d490