gcp-to-aws
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill processes untrusted user-supplied data such as Terraform configurations and application source code. While this creates a potential surface for indirect prompt injection, the skill orchestrator includes explicit instructions to ignore any embedded directives within user files and contains robust logic to treat the input strictly as data to be analyzed.
- Sensitive Data Redaction and Exclusion: The discovery phase demonstrates strong security hygiene by explicitly excluding known secret file patterns (e.g., .env, .pem, credentials.json) from its scanning scope. Furthermore, it includes automated redaction for potential secrets in discovered infrastructure configuration (e.g., passwords or API keys) before including them in output artifacts.
- Runtime Data Processing: For processing large billing exports and live discovery captures, the agent generates and executes temporary scripts. While this is a form of dynamic execution, these scripts are generated from internal templates and serve as a necessary mechanism for handling large datasets without exceeding context window constraints.
- Script Generation and Oversight: The skill produces shell scripts and migration code intended for user execution. These artifacts use a dry-run pattern by default and incorporate fail-fast checks for user-supplied variables, ensuring that users have full oversight and control before any changes are applied to their cloud environments.
Audit Metadata