azure-to-aws

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Managed Command Execution: The skill performs live resource discovery using the Azure CLI (az) which involves executing shell commands.
  • The discover-live.md file defines a strict security contract that limits the agent to an allowlist of read-only commands (e.g., list, show).
  • Data capture is restricted via JMESPath queries to select only metadata and names, explicitly excluding secret values like connection strings, API keys, or access tokens.
  • Explicit user consent is mandatory in the main window before any live capture commands are run.
  • Indirect Prompt Injection Surface: The agent processes untrusted external data such as Terraform configurations, application source code, and Azure resource tags.
  • SKILL.md incorporates a dedicated "Input Security" section that instructs the agent to treat user-supplied files strictly as data and to disregard any instructions or directives embedded within them.
  • This mitigation is designed to prevent malicious text in user files from overriding the skill's operational logic.
  • Stringent Secret and Data Handling: The skill implement multiple mechanisms to avoid capturing or leaking sensitive credentials.
  • discover-app-code.md enforces a "Secret-file exclusion" policy that automatically skips files like .env, *.key, *.p12, and credentials.json during scans.
  • extract-terraform.md explicitly forbids the reading of Terraform state files (.tfstate) which often contain resolved secrets, and requires that only attribute names (not values) be recorded for app settings.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:06 AM
Security Audit — agent-trust-hub — azure-to-aws