testing-mwaa-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [Command Execution]: The skill uses the AWS CLI to interact with Amazon MWAA environments. Specifically, it utilizes aws mwaa invoke-rest-api for provisioned environments and aws mwaa-serverless for serverless workflows.
  • [State-Changing Operations]: The skill is designed to trigger and re-trigger workflow runs. To mitigate the risk of unintended execution, the instructions require explicit user confirmation for every trigger, especially when targeting production environments.
  • [Separation of Concerns]: The skill follows the principle of least privilege by delegating resource mutations (like editing artifacts or creating environments) to a separate skill (authoring-mwaa-workflow) rather than performing them directly.
  • [Data Handling]: The instructions include a specific directive to avoid surfacing credentials or connection strings from logs or run details, which helps prevent accidental sensitive data exposure during monitoring.
  • [Execution Guardrails]: The skill implements a 'freshness gate' to ensure that it only adopts or triggers runs that match the current version of the deployed artifact, preventing the execution of stale code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 09:57 AM
Security Audit — agent-trust-hub — testing-mwaa-workflow