skills/awslabs/startups/heroku-to-aws/Gen Agent Trust Hub

heroku-to-aws

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Heroku CLI commands to inventory resources. This is strictly scoped to a pre-defined whitelist of read-only 'list' and 'info' commands as detailed in discover-live-capture.md. The skill includes explicit security logic to avoid capturing credentials or session tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data from files such as Procfile, app.json, and Terraform configurations.
  • Ingestion points: discover-terraform.md, discover-live.md, and discover-billing.md ingest workspace files.
  • Boundary markers: SKILL.md contains an 'Input Security' section that explicitly instructs the agent to treat these files as data and ignore any embedded instructions or directives.
  • Capability inventory: The skill has file-writing capabilities, network access via designed AWS resources (for the user to deploy), and command execution through the Heroku CLI.
  • Sanitization: Configuration variables are filtered to capture keys only, redacting all values to prevent sensitive data leakage.
  • [DYNAMIC_EXECUTION]: The skill utilizes a structured _exec pattern defined in INTERPRETER.md to dispatch non-interactive work (like resource discovery) to isolated sub-agents. These sub-agents are assigned specific capability tiers (ro, rw, rwx) to enforce the principle of least privilege.
  • [DYNAMIC_CONTEXT_INJECTION]: SKILL.md uses the ! syntax (e.g., !uv --version) to perform environment checks at skill load time. This is used for benign tool detection to ensure necessary utilities like uv or python3 are available for the migration process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 06:20 PM
Security Audit — agent-trust-hub — heroku-to-aws