aws-marketplace-metering

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill contains an attack surface where untrusted data could potentially enter the agent's context. (1) Ingestion points: The scripts/query_metering.py script fetches Event History from AWS CloudTrail, which includes metadata like dimension names and usage allocation tags provided by external buyers. (2) Boundary markers: Data is returned to the agent in structured JSON format, but there are no specific instructions or delimiters within the query output to warn the agent against executing instructions contained in the data. (3) Capability inventory: The agent context using this skill has permissions to execute shell scripts (scripts/deploy.sh), perform various AWS CLI commands, and interact with the AWS Marketplace APIs. (4) Sanitization: The script performs field-level filtering but does not sanitize the string content of the retrieved metadata for natural language instructions.
  • Command Execution: The skill requires the execution of shell commands and the AWS CLI to deploy SAM templates and perform operational queries. This is consistent with its stated purpose of managing AWS Marketplace integrations and infrastructure.
  • Sensitive Data Handling: The skill incorporates strong data privacy practices, such as the _mask helper in scripts like scripts/register.py and scripts/subscription.py to redact AWS account IDs and License ARNs in logs. The architecture also isolates buyer PII to regional tables, ensuring it remains separate from shared global infrastructure.
  • Infrastructure Security Guardrails: The provided templates and scripts implement several security best practices, including the attachment of AWS WAF to public endpoints, enforcement of encryption at rest for DynamoDB and SQS, and the use of IAM permissions boundaries to control role creation and prevent privilege escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:27 PM
Security Audit — agent-trust-hub — aws-marketplace-metering