amazon-sagemaker

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and the installer appears to be an official vendor npm package, so this is not malware-like. But it routes SageMaker access, auth flows, and action execution through Membrane's third-party CLI/service instead of AWS-native APIs, creating meaningful trust and data-flow risk; overall this is a medium-risk brokered integration rather than a benign direct AWS skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famazon-sagemaker%2F@1f63f4d505c89f802ad0c4c92d76dba3cb237cc2