amazon-opensearch-service
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Infrastructure Security: The skill enforces best practices by explicitly prohibiting the inclusion of sensitive data such as KMS ARNs, account IDs, or master usernames in its output.
- Remote Resource Retrieval: It provides instructions for using kubectl to apply configurations from the official OpenSearch Project repository on GitHub, which is a verified source for migration utilities.
- External Dependency Management: The skill suggest installing awscurl for SigV4-authenticated requests, which is a standard tool for AWS developer workflows.
- Least-Privilege Authorization: Provisioning examples for IAM roles and domain access policies include security conditions to mitigate confused-deputy risks and adhere to least-privilege principles.
- Data Ingestion Surface: While the skill processes user-supplied configuration files like schema.xml, it uses rigid report templates and specific 'case shapes' to ensure that input data is processed predictably, reducing the risk of unintended behavior.
Audit Metadata