ar-policy-debugger

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, including documents (PDF/TXT) and natural language feedback, to iteratively refine AWS Bedrock Automated Reasoning policies.
  • Ingestion points: scripts/iteratively_refine.py accepts document files via the --file argument and natural language strings via --feedback. scripts/apply_annotations.py ingests structured data from a JSON file via the --annotations-file argument.
  • Boundary markers: The scripts lack explicit boundary markers or instructions to the underlying model to ignore potentially malicious embedded directives within the provided documents or feedback.
  • Capability inventory: The skill possesses the capability to modify formal security policies using the UpdateAutomatedReasoningPolicy API call (invoked in scripts/apply_annotations.py, scripts/iteratively_refine.py, and scripts/resolve_ambiguities.py).
  • Sanitization: No evidence of sanitization, validation, or filtering of the external input content is present in the scripts before the data is passed to the Bedrock build workflows.
  • [COMMAND_EXECUTION]: The skill relies on several local Python scripts (apply_annotations.py, resolve_ambiguities.py, iteratively_refine.py) that must be executed to interact with AWS services. While these are functional tools for policy management, they perform operations on the cloud environment based on local file inputs provided to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:07 PM