amazon-opensearch-service

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Infrastructure Security: The skill enforces best practices by explicitly prohibiting the inclusion of sensitive data such as KMS ARNs, account IDs, or master usernames in its output.
  • Remote Resource Retrieval: It provides instructions for using kubectl to apply configurations from the official OpenSearch Project repository on GitHub, which is a verified source for migration utilities.
  • External Dependency Management: The skill suggest installing awscurl for SigV4-authenticated requests, which is a standard tool for AWS developer workflows.
  • Least-Privilege Authorization: Provisioning examples for IAM roles and domain access policies include security conditions to mitigate confused-deputy risks and adhere to least-privilege principles.
  • Data Ingestion Surface: While the skill processes user-supplied configuration files like schema.xml, it uses rigid report templates and specific 'case shapes' to ensure that input data is processed predictably, reducing the risk of unintended behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 06:40 AM
Security Audit — agent-trust-hub — amazon-opensearch-service