amazon-ses

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Command Injection Surface (Indirect Prompt Injection): The skill processes user-supplied inputs for domain names and subdomains which are subsequently interpolated into shell commands. Without explicit validation within the instructions, this presents an attack surface for command injection if the underlying execution environment lacks robust sanitization.
  • Ingestion points: The domain and mail_from_subdomain parameters defined in the references/setting-up-ses-domain-identity.md file.
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the command templates.
  • Capability inventory: Use of aws sesv2, aws route53, and dig commands via a system shell.
  • Sanitization: No specific filtering or validation steps for these parameters are prescribed within the skill scripts.
  • Resource Mutation Safeguards: The skill requires the agent to obtain explicit user confirmation before modifying Route 53 DNS records, providing a layer of human-in-the-loop protection for infrastructure changes.
  • Instructional Guidance: The recommendation to avoid mentioning the 72-hour DNS propagation window is a technical clarification based on typical service behavior and is not considered a concealment of malicious activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:21 PM
Security Audit — agent-trust-hub — amazon-ses