debugging-lambda-timeouts

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Data Processing Surface]: The skill ingests and analyzes external data including CloudWatch logs and user-provided Lambda function code. This is a common pattern for diagnostic tools, though it represents a surface where the agent processes content that could contain unexpected instructions. The skill handles this by constraining the agent's behavior to specific analysis and reporting tasks.
  • [AWS Command Execution]: The skill utilizes the platform's AWS CLI integration to perform read-only operations such as fetching metrics, configuration, and log data. These operations are restricted to diagnostic commands (e.g., get-metric-statistics, describe-log-groups, get-function-configuration) aligned with the skill's stated purpose.
  • [Indirect Prompt Injection Surface]:
  • Ingestion points: Function code provided in the lambda_code parameter and execution logs retrieved via aws logs start-query.
  • Boundary markers: The instructions do not define specific delimiters for separating processed data from the system prompt.
  • Capability inventory: The skill uses the call_aws tool to read logs, metrics, and function metadata across multiple steps in the SOP.
  • Sanitization: There is no explicit sanitization or filtering of the content retrieved from logs or provided in the code analysis step.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:00 AM