skills/aws/agent-toolkit-for-aws/creating-amazon-aurora-db-cluster-with-instances/Gen Agent Trust Hub
creating-amazon-aurora-db-cluster-with-instances
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Managed Credential Handling: The skill adheres to security best practices by utilizing AWS Secrets Manager to handle database passwords. It explicitly mandates the use of managed passwords and forbids the use of plaintext password parameters, which helps prevent sensitive credentials from appearing in logs or command history.
- Permission Validation: The procedure requires an initial check of AWS credentials and permissions using standard identity verification tools. This ensures that the agent is operating with the appropriate authorization before attempting to create infrastructure.
- Indirect Prompt Injection Surface: The skill processes user-provided parameters which are interpolated into AWS CLI commands via the call_aws tool.
- Ingestion points: Resource identifiers and configuration parameters in references/create-amazon-aurora-db-cluster-with-instances.md.
- Boundary markers: No specific delimiters or ignore instructions are present for the input parameters.
- Capability inventory: The skill utilizes call_aws to execute infrastructure management commands.
- Sanitization: The instructions do not specify explicit sanitization steps for the input parameters.
Audit Metadata