aws-cloud-monitoring
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the 'awslabs.cloudwatch-mcp-server' tool via uvx. This package is maintained by AWS Labs, which is an official and trusted organization.
- [SAFE]: The skill requires AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY for monitoring operations. These are managed through environment variables and are not hardcoded or exfiltrated.
- [PROMPT_INJECTION]: The skill processes external data from AWS CloudWatch logs and VPC flow logs. This ingestion point represents a surface for indirect prompt injection; however, because the tool is intended for analytical reporting and lacks high-privilege write capabilities for the ingested data, the risk is minimal and consistent with the skill's primary purpose.
Audit Metadata