llm-to-bedrock
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- Secure Credential Handling: The skill manages sensitive API keys for external LLM providers by storing them in a local environment file with restricted file-system permissions (chmod 600) and ensuring they are added to the project's .gitignore file to prevent accidental exposure.
- Data Privacy and Redaction: The included Python scripts implement proactive redaction logic to ensure that sensitive credentials are removed from failure text and error messages, preventing them from appearing in application logs, console output, or agent transcripts.
- Validated Subagent Architecture: The migration process is divided into distinct phases handled by specialized subagents. Each subagent's output is rigorously validated against strict JSON schemas before proceeding to the next step, ensuring structural integrity and minimizing the risk of processing malformed data.
- Trusted Communication Patterns: All network operations for model catalog resolution and performance benchmarking are directed to official endpoints of the respective technology providers, using standard authentication headers instead of query parameters.
Audit Metadata