model-deployment

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates Python scripts and Jupyter notebooks from predefined templates and instructs the agent to execute them using standard execution tools to perform model deployment operations.
  • [EXTERNAL_DOWNLOADS]: The skill automates the installation and upgrade of the official SageMaker Python SDK from standard package registries to ensure the environment supports newer deployment features.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from external AWS resources, including training job outputs and tags, which are used to determine deployment logic and interpolate values into code templates.
  • Ingestion points: Metadata retrieved via describe-training-job and list-tags in SKILL.md.
  • Boundary markers: None identified in the prompt interpolation logic.
  • Capability inventory: Includes file system writes (notebooks/scripts), command execution (python3), and network operations via AWS APIs.
  • Sanitization: None identified; reliance is placed on the structured use of data within code templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:58 PM
Security Audit — agent-trust-hub — model-deployment