ar-policy-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, including documents (PDF/TXT) and natural language feedback, to iteratively refine AWS Bedrock Automated Reasoning policies.
- Ingestion points:
scripts/iteratively_refine.pyaccepts document files via the--fileargument and natural language strings via--feedback.scripts/apply_annotations.pyingests structured data from a JSON file via the--annotations-fileargument. - Boundary markers: The scripts lack explicit boundary markers or instructions to the underlying model to ignore potentially malicious embedded directives within the provided documents or feedback.
- Capability inventory: The skill possesses the capability to modify formal security policies using the
UpdateAutomatedReasoningPolicyAPI call (invoked inscripts/apply_annotations.py,scripts/iteratively_refine.py, andscripts/resolve_ambiguities.py). - Sanitization: No evidence of sanitization, validation, or filtering of the external input content is present in the scripts before the data is passed to the Bedrock build workflows.
- [COMMAND_EXECUTION]: The skill relies on several local Python scripts (
apply_annotations.py,resolve_ambiguities.py,iteratively_refine.py) that must be executed to interact with AWS services. While these are functional tools for policy management, they perform operations on the cloud environment based on local file inputs provided to the agent.
Audit Metadata