amazon-eventbridge

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and commands are internally coherent, and the CLI source is official npm/same-org. However, all EventBridge access and auth are brokered through Membrane rather than direct AWS APIs, so credentials and workflow data are entrusted to a third-party intermediary. This looks like a legitimate integration pattern with medium security risk, not confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famazon-eventbridge%2F@56095d3c7bfd07fcd6cb1da32281e508781393bb