heroku-to-aws
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Heroku CLI commands to inventory resources. This is strictly scoped to a pre-defined whitelist of read-only 'list' and 'info' commands as detailed in
discover-live-capture.md. The skill includes explicit security logic to avoid capturing credentials or session tokens. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data from files such as
Procfile,app.json, and Terraform configurations. - Ingestion points:
discover-terraform.md,discover-live.md, anddiscover-billing.mdingest workspace files. - Boundary markers:
SKILL.mdcontains an 'Input Security' section that explicitly instructs the agent to treat these files as data and ignore any embedded instructions or directives. - Capability inventory: The skill has file-writing capabilities, network access via designed AWS resources (for the user to deploy), and command execution through the Heroku CLI.
- Sanitization: Configuration variables are filtered to capture keys only, redacting all values to prevent sensitive data leakage.
- [DYNAMIC_EXECUTION]: The skill utilizes a structured
_execpattern defined inINTERPRETER.mdto dispatch non-interactive work (like resource discovery) to isolated sub-agents. These sub-agents are assigned specific capability tiers (ro,rw,rwx) to enforce the principle of least privilege. - [DYNAMIC_CONTEXT_INJECTION]:
SKILL.mduses the!syntax (e.g.,!uv --version) to perform environment checks at skill load time. This is used for benign tool detection to ensure necessary utilities likeuvorpython3are available for the migration process.
Audit Metadata