heroku-to-aws

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • Command Execution: The skill utilizes the Heroku CLI for resource discovery and executes local Python scripts to validate migration reports and facilitate plan exports. These operations are governed by an explicit security contract that mandates read-only commands and redacts sensitive information such as configuration values and API tokens.\n- External Downloads: During the artifact generation phase, the skill instructs the download of a trusted Certificate Authority (CA) bundle from AWS (truststore.pki.rds.amazonaws.com). This is a standard procedure for ensuring secure, encrypted connections to RDS and Aurora databases.\n- Dynamic Execution: The skill generates Terraform configurations and migration scripts based on the detected Heroku environment. It also executes internal validation logic using Python to ensure the quality and safety of the produced infrastructure-as-code (IaC) artifacts.\n- Data Handling and Input Security: The skill processes various user-supplied files, including Terraform and billing data. It contains specific instructions to treat these inputs strictly as data and to ignore any embedded directives, which is a consideration for mitigating risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:06 AM
Security Audit — agent-trust-hub — heroku-to-aws