azure-to-aws
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user configuration and source code to identify Azure resources and AI workloads.
- Ingestion points:
discover-iac.md(Terraform/Bicep/ARM files) anddiscover-app-code.md(application source code and manifests). - Boundary markers: While the skill uses structured JSON for intermediate state, it processes free-form text from user files (resource names, tags).
SKILL.mdcontains a specific warning to the agent to treat these as untrusted data and ignore embedded instructions. - Capability inventory: The skill has filesystem write access (
_agent: rw) and can execute local python scripts for validation (generate.md). These capabilities are necessary for its primary purpose of generating migration artifacts. - Sanitization: The skill implements strict data filtering, specifically excluding secret values, connection strings, and sensitive file types like
.env,*.pem, and*.tfstateduring the discovery process. - [SAFE]: The skill is authored by a trusted entity (awslabs) and adheres to security best practices for AI agents, including least-privilege sub-agent configuration and rigorous data exclusion rules. All external references point to official AWS and service provider documentation.
Audit Metadata