upgrading-mwaa-environments
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- Sensitive Data Handling in CLI Arguments: The skill uses
aws mwaa invoke-rest-apito migrate Airflow variables and connections. Because these values are passed via the--bodyparameter, they may appear in cleartext in process lists, shell history, and audit logs. The skill provides explicit warnings about this behavior and recommends using a secrets backend (like AWS Secrets Manager or Parameter Store) to prevent sensitive data from traversing the API or CLI. - External Configuration and Data Ingestion: The skill fetches the MWAA version matrix from official AWS documentation and package constraints from the Apache Airflow GitHub repository. While these are trusted sources, the ingested data influences the upgrade path and package versions used in the environment.
- Ingestion points:
references/discovery-preflight.md(Step 3: version matrix fetch) andreferences/strategy-blue-green-fresh.md(Step 1: constraints fetch). - Boundary markers: The skill does not implement explicit delimiters or boundary markers for the external documentation content it processes.
- Capability inventory: The skill utilizes
aws mwaa create-environment,aws mwaa update-environment(inreferences/upgrade-engine.md), anddocker run(inSKILL.mdPhase 6) to perform significant infrastructure changes. - Sanitization: There is no evidence of sanitization or filtering of the content fetched from the external documentation sites.
- Automated Code Modification and Validation: The skill employs
ruffwith the--fixand--unsafe-fixesflags to automate the migration of Python code between Airflow versions. To mitigate potential issues introduced by automated fixes, the skill requires a manual re-scan for specific patterns and uses Docker containers for import validation before live deployment. - Resource Lifecycle Guardrails: The skill performs potentially destructive actions, including environment creation, modification, and deletion. These are protected by mandatory user confirmation checkpoints at every step, and the skill maintains a durable, resumable plan file to track the status of the upgrade process.
Audit Metadata