aws/agent-toolkit-for-aws aws-observability
Checked the catalogued skill at aws-observability.
F; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →
D; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →
B set by findings not listed in the stored summary
22 suppressed by AI triage
The absolute path is part of a documentation example, not executed code.
Hard‑coded absolute path used in example documentation, not user‑controlled.
Reference to a configuration file in example code, not malicious.
Absolute path used in a documented Dockerfile example, benign.
Curl command appears only in documentation; it does not execute automatically.
Hard‑coded path in example UserData commands, not exploited.
Outbound network call shown as part of example, not executed.
DNS lookup shown in documentation context, not exfiltration.
Reference to agent jar in example Docker run command, not malicious.
Environment variable setting in documentation, harmless.
The path refers to an intended configuration file in a documentation example, not malicious code.
The path points to a legitimate CloudWatch Agent binary used in a normal EC2 setup.
This is a reference to the CloudWatch Agent config file within instructional content, not a threat.
The snippet discusses legitimate networking options, not actual DNS tunneling or exfiltration.
Documentation shows legitimate absolute path usage in EC2 user data script.
Illustrative script starting CloudWatch Agent; absolute path is normal.
Repeated path reference in documentation; not malicious.
Context is about Docker networking, no actual DNS tunneling code; false positive.
The file references a raw GitHub URL only for documentation, not execution.
The absolute path is a standard Lambda system path cited in documentation, not a traversal vector.
The path is again a normal system directory reference in documentation, not an exploitable traversal.
The path is used in documentation as a sample argument, not actual code that could be exploited.