debugging-lambda-timeouts
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Data Processing Surface]: The skill ingests and analyzes external data including CloudWatch logs and user-provided Lambda function code. This is a common pattern for diagnostic tools, though it represents a surface where the agent processes content that could contain unexpected instructions. The skill handles this by constraining the agent's behavior to specific analysis and reporting tasks.
- [AWS Command Execution]: The skill utilizes the platform's AWS CLI integration to perform read-only operations such as fetching metrics, configuration, and log data. These operations are restricted to diagnostic commands (e.g.,
get-metric-statistics,describe-log-groups,get-function-configuration) aligned with the skill's stated purpose. - [Indirect Prompt Injection Surface]:
- Ingestion points: Function code provided in the
lambda_codeparameter and execution logs retrieved viaaws logs start-query. - Boundary markers: The instructions do not define specific delimiters for separating processed data from the system prompt.
- Capability inventory: The skill uses the
call_awstool to read logs, metrics, and function metadata across multiple steps in the SOP. - Sanitization: There is no explicit sanitization or filtering of the content retrieved from logs or provided in the code analysis step.
Audit Metadata