aws/agent-toolkit-for-aws amazon-keyspaces
Checked the catalogued skill at amazon-keyspaces.
C; retained sample includes a medium finding · SD-008 · what this rule accepts as a false positive →
D set by findings not listed
A set by no findings on this axis
42 suppressed by AI triage
The manifest statically references a fixed /tmp file for temporary output, not a user‑supplied path, so no real threat.
Fixed /tmp path used for temporary diagnostics; not user‑controlled, so not dangerous.
Hard‑coded /tmp path for temporary schema output; no security risk.
Script writes to a predetermined /tmp file; acceptable practice.
Same as above: non‑user‑supplied /tmp output.
Temporary file location is fixed, not a threat.
Explicit /tmp path for PDF generation is static and not exploitable.
Documentation shows a placeholder DNS hostname, not an active DNS lookup
Example curl command in documentation for downloading trusted certs, not an executed malicious outbound call
The snippet is a documentation example writing to /tmp, not executable code by the skill.
Same documentation example, harmless absolute path usage in context.
The text merely describes a DNS lookup used in documentation, not an actual DNS tunneling activity.
The path /tmp/keyspaces-calc.json is part of a command example in documentation, not an exploitation attempt.
Again, the path appears in a documentation example, not as a real path traversal exploit.
Example documentation using an absolute /tmp path, not executable code.
Documentation example using an absolute /tmp path, not executable.
Illustrative documentation with absolute /tmp path, safe.
Example output path in docs, not a security threat.
Documentation example path, not actionable code.
The line is part of a documentation example, not executable code.
It is a commented example in documentation, not actual code execution.
Documentation comments; no real file operation performed.
Example command in docs; safe and non-executable.
Commented reference in documentation, not active code.
Documentation example, no executable path traversal.
Documentation only; path is a sample, not real execution.
Illustrates example command usage in documentation, not actual file access, so benign.
Shows example command syntax in docs, not executing code, thus benign.
Sample command in documentation, no real file operation, benign.
Example showing multiple inputs in docs, safe context, benign.
Documentation example referencing file, not executed, benign.
Doc example showing third input, harmless.
Illustrates output file in docs, not real execution, benign.
Documentation of tee command example, no risk, benign.
Documentation references credential paths only for informational purposes, not to access them.
Link list mentions credential guidance, not code that reads credentials.
Reference to SigV4 authentication documentation is benign, not an actual credential access.
The absolute path references are only shown in comment examples, not used in executable code.
The path is part of documentation, not code execution, so no traversal risk.
Reference appears only in usage comments, not actual file access.
Commented example path; no runtime traversal.
Output path shown in comments only, not hardcoded in executable logic.