agents-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Command Execution: The skill utilizes shell commands to interact with the AWS CLI and AgentCore CLI. This includes retrieving account identity, listing models, and performing deployments. These actions are necessary for managing cloud infrastructure.\n- Indirect Prompt Injection Surface: The skill reads agentcore.json and aws-targets.json to configure deployment settings. While standard, this represents a potential surface for indirect prompt injection if these files were to contain untrusted data. Developers should ensure configuration files originate from trusted sources.\n
  • Ingestion points: agentcore/agentcore.json, agentcore/aws-targets.json (SKILL.md)\n
  • Boundary markers: Not explicitly defined in the instruction set.\n
  • Capability inventory: Includes Bash for command execution and Read for file access.\n
  • Sanitization: No explicit sanitization of JSON content before use in CLI arguments is detailed.\n- External Dependencies: The skill suggests the use of npx cdk bootstrap and agentcore update. These involve fetching resources from external registries (NPM and vendor-specific updates), which is common in development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:26 PM
Security Audit — agent-trust-hub — agents-deploy