ecs-recon
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by 'aws-samples', which is a recognized repository for AWS architectural examples and adheres to legitimate vendor resource patterns.
- [SAFE]: The skill implements a strictly read-only model, utilizing 'aws ecs describe-' and 'list-' commands to gather environmental context without attempting any resource modification.
- [SAFE]: Security-aware instructions are included that explicitly prevent the AI agent from reproducing 'containerDefinitions[].environment' or non-awslogs 'logConfiguration.options' in its reports, effectively mitigating the risk of unintentional credential exposure.
- [SAFE]: All external references point to official Amazon Web Services documentation (aws.amazon.com), ensuring that all instructional data sources are trusted.
- [SAFE]: The reconnaissance logic is transparent and focuses on discovering clusters, services, and task definitions as per its stated purpose, with no evidence of obfuscation, persistence, or data exfiltration.
Audit Metadata