aws-lambda-web-functions
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill provides instructions for building web applications that process untrusted data from HTTP requests, including paths, headers, and request bodies. This creates a surface for potential indirect prompt injection if the ingested data is subsequently processed by an AI agent without proper sanitization. The documentation mitigates this by explicitly advising on input validation and providing examples of security middleware like
helmetand HMAC signature verification for webhooks. - Evidence: Detailed guidance in
references/iam-and-security.mdandreferences/architecture-patterns.md(SSR and Webhook sections). - [Command Execution Patterns]: The skill defines workflows using the
aws lambda-webCLI for resource management and standard Node.js tooling for development. These commands are necessary for the skill's primary purpose of cloud deployment and are documented with security contexts, such as using IAM least-privilege policies. - Evidence: Deployment procedures outlined in
SKILL.mdandreferences/deployment.md.
Audit Metadata