prompt-library-for-startups

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill includes a specialized prompt for support ticket triage that is designed to process untrusted customer data. This represents a surface for indirect prompt injection, which the skill addresses with specific defensive instructions.
  • Ingestion Points: Found in references/prompt-library/ai-support-ticket-triage-and-routing-assistant.md, where the agent processes customer-submitted support tickets.
  • Boundary Markers: The prompt includes explicit defensive markers instructing the model to treat input as untrusted data and ignore any instructions or override attempts embedded within the ticket content.
  • Capability Inventory: The agent utilizes AWS services such as bedrock:InvokeModel and comprehend:DetectSentiment to perform its analysis.
  • Sanitization: The agent is instructed to produce output strictly adhering to a defined JSON schema, which helps constrain the model's response and prevent execution of injected commands.
  • References to External Repositories: The skill directs users to download and install operational agents from the aws-samples organization on GitHub. These references target a well-known service associated with the vendor and are used to provide pre-built automation for tasks like cost monitoring and quota management.
  • Infrastructure Command Execution: The library contains prompts that generate and execute shell commands, AWS CLI operations, and infrastructure-as-code deployments (e.g., cdk deploy, terraform apply). These are fundamental to the skill's primary purpose as a DevOps and architecture assistant, providing the necessary automation for cloud environment setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 07:56 PM
Security Audit — agent-trust-hub — prompt-library-for-startups