deploy
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external codebase data to determine architectural needs and generate infrastructure code. This creates an attack surface where instructions embedded in the codebase could attempt to influence the agent's behavior.
- Ingestion points:
SKILL.mddefines a workflow that scans user-provided codebase for frameworks, databases, and dependencies. - Boundary markers: The instructions do not specify the use of delimiters or specific boundary markers when the agent reads the codebase content.
- Capability inventory: The skill is designed to generate Infrastructure as Code (IaC) and perform deployments using the
awsiacandawsknowledgeMCP servers. - Sanitization: There is no mention of sanitizing or validating the ingested codebase content before it is used for infrastructure generation.
- [DYNAMIC_EXECUTION]: The skill involves the generation and subsequent execution of infrastructure scripts based on analyzed project data.
- Evidence: The 'Generate' and 'Deploy' steps in
SKILL.mdinvolve writing CDK, Terraform, or CloudFormation code and executing it after security scans.
Audit Metadata