authoring-mwaa-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill ingests data from external sources including S3 buckets (requirements.txt, startup scripts) and the MWAA REST API (variables, connections, and DAG metadata). This data is processed by the agent to inform code generation, package validation, and environment configuration.
  • Ingestion points: references/authoring-provisioned-dag.md (reads requirements.txt and startup scripts from S3; reads connections and variables via invoke-rest-api).
  • Boundary markers: Not explicitly defined for the ingested data.
  • Capability inventory: references/deploying-mwaa.md (executes create-environment, update-environment, put-role-policy, and S3 uploads).
  • Sanitization: The skill provides logic to validate package versions and operator availability but does not specify sanitization for the content of variables or connections before processing.
  • [Identity and Access Management (IAM) Operations]: The skill includes instructions to modify execution roles using aws iam put-role-policy to ensure the generated workflows have the necessary permissions. While this is a sensitive operation, it is governed by a mandatory 'hard gate' requiring explicit user confirmation and an assessment of the impact on the environment's security posture.
  • [External Configuration Fetching]: The skill retrieves Apache Airflow constraints from a public GitHub repository to validate dependency compatibility. This represents a standard practice for maintaining stable environments and targets a well-known, community-maintained source.
  • [State-Mutating Command Execution]: Several deployment steps involve state-mutating AWS CLI commands (e.g., creating environments, updating workflows, and uploading artifacts to S3). These are core to the skill's purpose and are implemented with safety prompts and warnings for production targets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 09:58 AM
Security Audit — agent-trust-hub — authoring-mwaa-workflow