Back to skill

Security audit

Aws Agentcore Langgraph Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward AWS AgentCore and LangGraph deployment guide, with one cleanup command that users should run carefully.

Before installing or using this skill, make sure you are comfortable letting your agent run AWS AgentCore CLI commands. Use least-privilege AWS credentials, confirm the region and target agent before launch or destroy operations, and avoid storing real API keys in shared shell history or repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The documentation includes a destructive cleanup command without warning that it may delete deployed resources. In an agent skill with `exec` capability, users may copy-paste lifecycle commands directly, increasing the risk of unintended resource deletion and service disruption.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.