model-deployment
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates Python scripts and Jupyter notebooks from predefined templates and instructs the agent to execute them using standard execution tools to perform model deployment operations.
- [EXTERNAL_DOWNLOADS]: The skill automates the installation and upgrade of the official SageMaker Python SDK from standard package registries to ensure the environment supports newer deployment features.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from external AWS resources, including training job outputs and tags, which are used to determine deployment logic and interpolate values into code templates.
- Ingestion points: Metadata retrieved via
describe-training-jobandlist-tagsinSKILL.md. - Boundary markers: None identified in the prompt interpolation logic.
- Capability inventory: Includes file system writes (notebooks/scripts), command execution (python3), and network operations via AWS APIs.
- Sanitization: None identified; reliance is placed on the structured use of data within code templates.
Audit Metadata