Back to skill

Security audit

Aws Agent Orchestrator Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a deployment guide for AWS Bedrock AgentCore and its risky commands are mostly purpose-aligned, but users should be careful with cloud deployment and teardown actions.

Install only if you intend to let the agent help run local package installs and AWS AgentCore CLI commands. Before running deployment or destroy commands, verify the active AWS profile, account, region, agent name, and whether the target is production; treat agentcore destroy as destructive cloud cleanup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The skill documents `agentcore destroy` as a supported command for a deployment assistant without any guardrails, confirmation guidance, or clear warning that it tears down live cloud resources. In a tool-enabled agent setting, this increases the chance that a user or downstream agent invokes destructive infrastructure actions unintentionally.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation includes a destructive teardown command with no cautionary note, preconditions, or confirmation pattern. In an agent skill that permits `exec`, such omissions materially raise the risk of accidental deletion of deployed infrastructure and service downtime.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.