llm-to-bedrock

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted data, specifically source code and log files, which creates a surface for indirect prompt injection. This is mitigated through structured processing and validation steps.
  • Ingestion points: User-specified source code repository paths, provided log files, and migration metadata in files such as analysis.json and preferences.json (found in SKILL.md and scripts/validate_result.py).
  • Boundary markers: Every phase transition is guarded by a deterministic JSON schema validator (scripts/validate_result.py) and explicit user confirmation gates.
  • Capability inventory: The skill possesses capabilities for repository management (git), file writes, and Bedrock/external AI API interactions.
  • Sanitization: Python scripts (scripts/source_baseline.py and scripts/resolve_source_model.py) include advanced redaction logic that identifies and removes secret variants from error messages and output results.
  • [SAFE]: Sensitive credential management is implemented correctly. API keys are collected via silent terminal input and written to locally ignored files with restricted permissions (chmod 600), preventing keys from being logged in the conversation transcript.
  • [SAFE]: The skill uses a pinned dependency environment via uv and limits network activity to official AI provider endpoints and verified AWS services.
  • [SAFE]: Privilege management is handled appropriately; the skill uses least-privilege IAM policy generation for Bedrock access, reducing the potential impact of credential misuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:47 PM
Security Audit — agent-trust-hub — llm-to-bedrock