aws-storage

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [Security Guidance and Best Practices]: The skill explicitly instructs the agent to recommend enabling encryption at rest and in transit, and to advise on least-privileged IAM policies. It specifically highlights the use of condition keys (e.g., aws:SourceArn) to prevent cross-service confused deputy attacks.
  • [Use of Trusted Resources]: External links and specialized skill references point exclusively to official AWS documentation domains and authorized AWS GitHub repositories. These are recognized as safe sources for technical guidance.
  • [Data Ingestion Surface]: The skill processes user-provided queries to categorize requests, which represents an entry point for potential indirect prompt injection. However, the skill employs structured intent classification to maintain scope. • Ingestion points: User-provided queries processed in Step 1 of SKILL.md. • Boundary markers: Intent classification logic and decision factor tables guide the agent's response scope. • Capability inventory: The agent utilizes documentation search tools (search_documentation, read_documentation) and the AWS CLI to verify specifications. • Sanitization: The skill relies on grounding instructions and official documentation retrieval rather than the direct execution of unsanitized user commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 05:53 PM
Security Audit — agent-trust-hub — aws-storage