resilience-hub-failure-mode-assessment

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [AWS Service Integration]: The skill interacts exclusively with the AWS Resilience Hub service using standard AWS CLI commands or the AWS MCP server. These interactions occur within the user's authenticated environment and are restricted to the service's API surface.
  • [Data Protection Guidance]: The skill includes specific instructions to secure assessment outputs, recommending the use of S3 server-side encryption (SSE-S3 or SSE-KMS), blocking public access, and using IAM condition keys (e.g., aws:SourceArn) to prevent unauthorized access to report buckets.
  • [Identity and Access Management]: Security considerations emphasize the principle of least privilege, advising users to scope the assessment invoker role to read-only discovery of necessary resource types.
  • [Operational Safeguards]: The workflow includes mandatory verification steps and cost estimates, requiring explicit user confirmation before initiating billable assessments. It also provides clear polling constraints to prevent API throttling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 11:09 AM
Security Audit — agent-trust-hub — resilience-hub-failure-mode-assessment