skills/awslabs/startups/aws-architect/Gen Agent Trust Hub

aws-architect

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill mandates a security review pass by spawning a specific security-focused subagent (iac-reviewer) for any generated architecture, which serves as a critical safety check for infrastructure recommendations.
  • [SAFE]: The architecture evaluation criteria explicitly prioritize core security principles, including identity and access management (IAM) best practices, data encryption, and network isolation.
  • [SAFE]: Tool integration is limited to verified AWS documentation and cost estimation MCP plugins, which are consistent with the skill's purpose and the developer's identity (awslabs).
  • [SAFE]: While the skill gathers user requirements during a discovery phase, the potential risk of indirect prompt injection is mitigated by the structured review process and the read-only nature of the documentation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:30 AM
Security Audit — agent-trust-hub — aws-architect