Scanned skills

aws/agent-toolkit-for-aws amazon-bedrock

Checked the catalogued skill at amazon-bedrock.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 4
F Security

F; retained sample includes a critical finding · SD-002 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a critical finding · SD-004 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

4 findings
securitycritical SD-002
references/model-invocation.md
securitycritical SD-002
references/prompt-engineering-by-model.md
permission_hygienecritical SD-004
scripts/fetch_bedrock_agent.py
securitycritical SD-013
scripts/fetch_bedrock_agent.py
2 suppressed by AI triage
securitymedium SD-008 benign_example
references/agentcore-payments-wiring.md

The base64 decoding is applied to a standard payment challenge header (x402 challenge) which is a legitimate use, not malicious obfuscation.

securityhigh SD-007 benign_example
references/agentcore-runtime-container-build.md

Documentation example shows a curl to localhost for testing, not a malicious outbound call.