Glad they were able to automatically detect/catch this. There seems to be so much bloat when dependencies get pulled in.
Wonder if something like pledge and unveil around library code could be helpful; perhaps library code needs to be separated out into a separate process that would not have reason to access AWS keys.
Also, looking at the screenshot, could a simple programming searching for URLs in the library code help in this case?
Looks like they removed the modules, so one can't examine them any more.