debugging-mwaa-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFE
Full Analysis
- Safe Diagnostic Practices: The skill focuses on list and describe operations to identify root causes. It explicitly instructs the agent to never execute state-mutating commands (such as clearing tasks or updating environment configurations) autonomously, ensuring the user remains in control of the production environment.
- IAM Security Guidance: When addressing access denials, the skill provides structured guidance for generating minimal IAM policy statements. This encourages the principle of least privilege by targeting specific resources and actions instead of recommending broad or wildcard permissions.
- External Resource Verification: The skill references official AWS documentation for technical details regarding Serverless operators. These links point to a trusted vendor domain and provide necessary technical context without security risk.
- Handling of Untrusted Data: The skill processes information from CloudWatch logs and API responses, which is inherent to its diagnostic function. The instructions mitigate potential indirect prompt injection risks by defining a strict output structure and requiring user review for all remediation steps.
Audit Metadata