prompt-library-for-startups
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill includes a specialized prompt for support ticket triage that is designed to process untrusted customer data. This represents a surface for indirect prompt injection, which the skill addresses with specific defensive instructions.
- Ingestion Points: Found in
references/prompt-library/ai-support-ticket-triage-and-routing-assistant.md, where the agent processes customer-submitted support tickets. - Boundary Markers: The prompt includes explicit defensive markers instructing the model to treat input as untrusted data and ignore any instructions or override attempts embedded within the ticket content.
- Capability Inventory: The agent utilizes AWS services such as
bedrock:InvokeModelandcomprehend:DetectSentimentto perform its analysis. - Sanitization: The agent is instructed to produce output strictly adhering to a defined JSON schema, which helps constrain the model's response and prevent execution of injected commands.
- References to External Repositories: The skill directs users to download and install operational agents from the
aws-samplesorganization on GitHub. These references target a well-known service associated with the vendor and are used to provide pre-built automation for tasks like cost monitoring and quota management. - Infrastructure Command Execution: The library contains prompts that generate and execute shell commands, AWS CLI operations, and infrastructure-as-code deployments (e.g.,
cdk deploy,terraform apply). These are fundamental to the skill's primary purpose as a DevOps and architecture assistant, providing the necessary automation for cloud environment setup.
Audit Metadata