skills/aws-samples/sample-well-architected-skills-and-steering/aws-well-architected-framework-review/Gen Agent Trust Hub
aws-well-architected-framework-review
Fail
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: CRITICALNO_CODE
Full Analysis
- [SAFE]: The skill is a documentation-only resource consisting of 198 Markdown files. It contains no executable scripts, binaries, or active command injections. All logic is implemented via natural language instructions for AI agents.
- [EXTERNAL_DOWNLOADS]: Automated scanners identified several URLs on the
aws-samples.github.iodomain as potentially malicious. These are confirmed as safe vendor resources belonging to the skill author (aws-samples). The links provide documentation for AWS reference architectures and do not involve untrusted code execution. - [SAFE]: Five documentation files in the
references/lenses/devops-guidance/directory were flagged as malware. Analysis of these files (e.g.,DLCD04.md,DLEAC04.md) confirms they are plain Markdown text containing guidance on continuous delivery and configuration. The alerts are false positives likely triggered by the use of strings like 'inject code' used in the context of describing security best practices (e.g., 'Humans should not... have the ability to inject code'). - [NO_CODE]: The skill does not distribute any code files (Python, Node.js, Shell, etc.). It defines a workflow that utilizes the agent's internal capabilities and the
Tasktool for parallel processing of the Well-Architected Framework pillars. - [SAFE]: The skill logic uses a 'narrow-scope subagent' pattern to ensure thorough evaluation of all 307 best practices, which is an architectural choice to handle model context constraints and does not introduce security risks.
Recommendations
- CRITICAL: 6 file(s) identified as malware by FileRep - DO NOT USE
- Contains 6 malicious URL(s) - DO NOT USE
Audit Metadata