amazon-ses
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Command Injection Surface (Indirect Prompt Injection): The skill processes user-supplied inputs for domain names and subdomains which are subsequently interpolated into shell commands. Without explicit validation within the instructions, this presents an attack surface for command injection if the underlying execution environment lacks robust sanitization.
- Ingestion points: The
domainandmail_from_subdomainparameters defined in thereferences/setting-up-ses-domain-identity.mdfile. - Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the command templates.
- Capability inventory: Use of
aws sesv2,aws route53, anddigcommands via a system shell. - Sanitization: No specific filtering or validation steps for these parameters are prescribed within the skill scripts.
- Resource Mutation Safeguards: The skill requires the agent to obtain explicit user confirmation before modifying Route 53 DNS records, providing a layer of human-in-the-loop protection for infrastructure changes.
- Instructional Guidance: The recommendation to avoid mentioning the 72-hour DNS propagation window is a technical clarification based on typical service behavior and is not considered a concealment of malicious activity.
Audit Metadata