Scanned skills
aws/agent-toolkit-for-aws amazon-bedrock
Checked the catalogued skill at amazon-bedrock.
F AI-triaged 4
F Security
F; retained sample includes a critical finding · SD-002 · what this rule accepts as a false positive →
F Permissions
F; retained sample includes a critical finding · SD-004 · what this rule accepts as a false positive →
A Transparency
A set by no findings on this axis
4 findings
references/model-invocation.md
references/prompt-engineering-by-model.md
scripts/fetch_bedrock_agent.py
scripts/fetch_bedrock_agent.py
2 suppressed by AI triage
references/agentcore-payments-wiring.md
The base64 decoding is applied to a standard payment challenge header (x402 challenge) which is a legitimate use, not malicious obfuscation.
references/agentcore-runtime-container-build.md
Documentation example shows a curl to localhost for testing, not a malicious outbound call.