Scanned skills

aws/agent-toolkit-for-aws amazon-keyspaces

Checked the catalogued skill at amazon-keyspaces.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
D AI-triaged 199
C Security

C; retained sample includes a medium finding · SD-008 · what this rule accepts as a false positive →

D Permissions

D set by findings not listed

A Transparency

A set by no findings on this axis

showing 10 of 199
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
securitymedium SD-008
assets/data/mcs.json
42 suppressed by AI triage
permission_hygienehigh SD-003 benign_example
SKILL.md

The manifest statically references a fixed /tmp file for temporary output, not a user‑supplied path, so no real threat.

permission_hygienehigh SD-003 benign_example
SKILL.md

Fixed /tmp path used for temporary diagnostics; not user‑controlled, so not dangerous.

permission_hygienehigh SD-003 benign_example
SKILL.md

Hard‑coded /tmp path for temporary schema output; no security risk.

permission_hygienehigh SD-003 benign_example
SKILL.md

Script writes to a predetermined /tmp file; acceptable practice.

permission_hygienehigh SD-003 benign_example
SKILL.md

Same as above: non‑user‑supplied /tmp output.

permission_hygienehigh SD-003 benign_example
SKILL.md

Temporary file location is fixed, not a threat.

permission_hygienehigh SD-003 benign_example
SKILL.md

Explicit /tmp path for PDF generation is static and not exploitable.

securityhigh SD-022 benign_example
references/connection-troubleshooting.md

Documentation shows a placeholder DNS hostname, not an active DNS lookup

transparencymedium SD-007 benign_example
references/connection-troubleshooting.md

Example curl command in documentation for downloading trusted certs, not an executed malicious outbound call

permission_hygienehigh SD-003 benign_example
references/mode-1-manual-inputs.md

The snippet is a documentation example writing to /tmp, not executable code by the skill.

permission_hygienehigh SD-003 benign_example
references/mode-1-manual-inputs.md

Same documentation example, harmless absolute path usage in context.

securityhigh SD-022 benign_example
references/mode-2-cassandra-diagnostics.md

The text merely describes a DNS lookup used in documentation, not an actual DNS tunneling activity.

permission_hygienehigh SD-003 benign_example
references/mode-2-cassandra-diagnostics.md

The path /tmp/keyspaces-calc.json is part of a command example in documentation, not an exploitation attempt.

permission_hygienehigh SD-003 benign_example
references/mode-2-cassandra-diagnostics.md

Again, the path appears in a documentation example, not as a real path traversal exploit.

permission_hygienehigh SD-003 benign_example
references/mode-3-compatibility.md

Example documentation using an absolute /tmp path, not executable code.

permission_hygienehigh SD-003 benign_example
references/mode-3-compatibility.md

Documentation example using an absolute /tmp path, not executable.

permission_hygienehigh SD-003 benign_example
references/mode-3-compatibility.md

Illustrative documentation with absolute /tmp path, safe.

permission_hygienehigh SD-003 benign_example
references/mode-3-compatibility.md

Example output path in docs, not a security threat.

permission_hygienehigh SD-003 benign_example
references/mode-3-compatibility.md

Documentation example path, not actionable code.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

The line is part of a documentation example, not executable code.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

It is a commented example in documentation, not actual code execution.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

Documentation comments; no real file operation performed.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

Example command in docs; safe and non-executable.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

Commented reference in documentation, not active code.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

Documentation example, no executable path traversal.

permission_hygienehigh SD-003 benign_example
references/mode-4-sql-migration.md

Documentation only; path is a sample, not real execution.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Illustrates example command usage in documentation, not actual file access, so benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Shows example command syntax in docs, not executing code, thus benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Sample command in documentation, no real file operation, benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Example showing multiple inputs in docs, safe context, benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Documentation example referencing file, not executed, benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Doc example showing third input, harmless.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Illustrates output file in docs, not real execution, benign.

permission_hygienehigh SD-003 benign_example
references/pdf-reporting.md

Documentation of tee command example, no risk, benign.

permission_hygienecritical SD-004 benign_example
references/security-considerations.md

Documentation references credential paths only for informational purposes, not to access them.

permission_hygienecritical SD-004 benign_example
references/security-considerations.md

Link list mentions credential guidance, not code that reads credentials.

permission_hygienecritical SD-004 benign_example
references/security-considerations.md

Reference to SigV4 authentication documentation is benign, not an actual credential access.

permission_hygienehigh SD-003 benign_example
scripts/generate-pdf.ts

The absolute path references are only shown in comment examples, not used in executable code.

permission_hygienehigh SD-003 benign_example
scripts/generate-pdf.ts

The path is part of documentation, not code execution, so no traversal risk.

permission_hygienehigh SD-003 benign_example
scripts/generate-pdf.ts

Reference appears only in usage comments, not actual file access.

permission_hygienehigh SD-003 benign_example
scripts/generate-pdf.ts

Commented example path; no runtime traversal.

permission_hygienehigh SD-003 benign_example
scripts/generate-pdf.ts

Output path shown in comments only, not hardcoded in executable logic.