ecs-recon

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by 'aws-samples', which is a recognized repository for AWS architectural examples and adheres to legitimate vendor resource patterns.
  • [SAFE]: The skill implements a strictly read-only model, utilizing 'aws ecs describe-' and 'list-' commands to gather environmental context without attempting any resource modification.
  • [SAFE]: Security-aware instructions are included that explicitly prevent the AI agent from reproducing 'containerDefinitions[].environment' or non-awslogs 'logConfiguration.options' in its reports, effectively mitigating the risk of unintentional credential exposure.
  • [SAFE]: All external references point to official Amazon Web Services documentation (aws.amazon.com), ensuring that all instructional data sources are trusted.
  • [SAFE]: The reconnaissance logic is transparent and focuses on discovering clusters, services, and task definitions as per its stated purpose, with no evidence of obfuscation, persistence, or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 07:19 AM
Security Audit — agent-trust-hub — ecs-recon