operate-on-aws

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [IAM Role and Resource Management]: The skill is designed to create IAM roles and Agent Spaces within a user's AWS account to enable autonomous operations. These are high-privilege actions that allow the agent to read telemetry and architecture metadata across the account. To mitigate risks, the skill implements 'hard gates' (ACCESS and DISCLOSE phases) that require explicit user confirmation before any write operations occur. The trust policies include conditions like aws:SourceAccount and aws:SourceArn to prevent cross-account access issues.
  • [Credential and Session Access]: The skill reads existing AWS credentials, SSO session tokens from ~/.aws/sso/cache/, and configuration files to authenticate with AWS services. This access is necessary for the skill's primary function of operating on AWS infrastructure. It also checks billing data via aws billing get-credits, which requires specific root-level enablement in the AWS account.
  • [Data Handling and Code Egress]: The skill processes CloudWatch logs which may contain personally identifiable information (PII). Additionally, the 'Release-readiness review' feature may clone source code into an AWS-managed verification environment for automated testing. These behaviors are explicitly disclosed to the user, and the code-egress feature is gated by a separate consent requirement and defaults to off.
  • [Indirect Prompt Injection Defenses]: The instructions include specific guidance for the agent to treat external data (like CloudWatch logs or tool outputs) as information to be reported, rather than instructions to be followed. It explicitly warns the agent not to execute commands found within reports and to distinguish trust based on data provenance rather than field labels.
  • [External Dependency Management]: The skill utilizes uvx mcp-proxy-for-aws@latest to establish a SigV4-authenticated MCP connection. While using an unpinned version (@latest) is a common pattern for vendor-provided proxies, it is a dependency consideration that relies on the integrity of the vendor's publication pipeline.
  • [Autonomous Operational Capabilities]: The skill is designed to perform setup and configuration tasks in the background while a user manages active incidents. While this involves autonomous execution of shell commands, the skill's architecture ensures that these actions only proceed after informed consent has been established during the initial setup phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 06:08 PM
Security Audit — agent-trust-hub — operate-on-aws