aws-serverless
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains standard boilerplate code and AWS SAM templates for serverless development. All code snippets follow established AWS best practices, such as initializing database clients outside the handler function for execution environment reuse.
- [PROMPT_INJECTION]: No instructions were found that attempt to override the AI agent's behavior, bypass safety guidelines, or extract system prompts.
- [DATA_EXFILTRATION]: No evidence of unauthorized data access or external transmission. The skill correctly demonstrates using environment variables for configuration (e.g.,
TABLE_NAME) and adheres to the principle of least privilege in the provided IAM policies (DynamoDBReadPolicy). - [REMOTE_CODE_EXECUTION]: The skill does not perform any remote script downloads or arbitrary command execution. It uses well-known, official libraries including the AWS SDK for JavaScript and Boto3 for Python.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or credentials were found. The skill suggests secure practices by referencing environment variables for resource names.
- [INDIRECT_PROMPT_INJECTION]: While the Lambda handlers ingest external data (e.g.,
event.body), the snippets are provided as static templates for developers. They do not introduce immediate vulnerabilities to the AI agent processing the skill itself.
Audit Metadata