aws-well-architected-review
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill ingests and analyzes external workload code, infrastructure-as-code templates, and architecture descriptions to produce review findings. Processing external data represents a consideration for indirect prompt injection. (1) Ingestion points: infrastructure-as-code, application code, and CI/CD configurations (SKILL.md, discovery-procedure.md). (2) Boundary markers: uses a structured per-pillar analysis pattern to isolate workload context (evaluation-procedure.md). (3) Capability inventory: performs network requests to official documentation and writes to local scratch files (phase-live-inventory.md). (4) Sanitization: includes explicit instructions to identify and redact sensitive credentials found in discovered code (discovery-procedure.md).
- [Data Exposure Protections]: The discovery procedure mandates the identification and redaction of hardcoded secrets, such as IAM keys and passwords, ensuring sensitive values are not included in report outputs or evidence logs.
- [Trusted Documentation Retrieval]: Framework data is retrieved exclusively from official AWS documentation (docs.aws.amazon.com) using secure HTTPS or platform-native documentation tools, ensuring the source material remains authoritative.
- [Confidentiality and Security Best Practices]: The skill incorporates comprehensive guidance for handling sensitive findings, recommending temporary credentials, encrypted storage for artifacts, and marking all deliverables with confidentiality banners.
Audit Metadata