testing-mwaa-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [Command Execution]: The skill uses the AWS CLI to interact with Amazon MWAA environments. Specifically, it utilizes
aws mwaa invoke-rest-apifor provisioned environments andaws mwaa-serverlessfor serverless workflows. - [State-Changing Operations]: The skill is designed to trigger and re-trigger workflow runs. To mitigate the risk of unintended execution, the instructions require explicit user confirmation for every trigger, especially when targeting production environments.
- [Separation of Concerns]: The skill follows the principle of least privilege by delegating resource mutations (like editing artifacts or creating environments) to a separate skill (
authoring-mwaa-workflow) rather than performing them directly. - [Data Handling]: The instructions include a specific directive to avoid surfacing credentials or connection strings from logs or run details, which helps prevent accidental sensitive data exposure during monitoring.
- [Execution Guardrails]: The skill implements a 'freshness gate' to ensure that it only adopts or triggers runs that match the current version of the deployed artifact, preventing the execution of stale code.
Audit Metadata