ecs-build

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill generates infrastructure code based on user-supplied requirements, which is a standard indirect prompt injection surface. The skill mitigates this through structured workflows and strict architectural rules.
  • Ingestion points: Requirements are gathered from a YAML file or interactive prompts as defined in the Workflow section of SKILL.md.
  • Boundary markers: The skill instructions emphasize following established companion skill conventions and pinning versions, providing a framework for safe code generation.
  • Capability inventory: The skill has the capability to generate multiple Terraform files and includes a utility script (scripts/validate_project.sh) that invokes the terraform CLI.
  • Sanitization: Generation is directed toward established modules and baseline defaults, reducing the risk of malicious requirement interpolation.
  • [COMMAND_EXECUTION]: The skill provides scripts/validate_project.sh, which executes local commands including terraform fmt and terraform validate to ensure the integrity of the generated project. These are standard development tools and do not involve remote code execution or unsafe command patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:56 AM