llm-to-bedrock
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted data, specifically source code and log files, which creates a surface for indirect prompt injection. This is mitigated through structured processing and validation steps.
- Ingestion points: User-specified source code repository paths, provided log files, and migration metadata in files such as
analysis.jsonandpreferences.json(found inSKILL.mdandscripts/validate_result.py). - Boundary markers: Every phase transition is guarded by a deterministic JSON schema validator (
scripts/validate_result.py) and explicit user confirmation gates. - Capability inventory: The skill possesses capabilities for repository management (git), file writes, and Bedrock/external AI API interactions.
- Sanitization: Python scripts (
scripts/source_baseline.pyandscripts/resolve_source_model.py) include advanced redaction logic that identifies and removes secret variants from error messages and output results. - [SAFE]: Sensitive credential management is implemented correctly. API keys are collected via silent terminal input and written to locally ignored files with restricted permissions (
chmod 600), preventing keys from being logged in the conversation transcript. - [SAFE]: The skill uses a pinned dependency environment via
uvand limits network activity to official AI provider endpoints and verified AWS services. - [SAFE]: Privilege management is handled appropriately; the skill uses least-privilege IAM policy generation for Bedrock access, reducing the potential impact of credential misuse.
Audit Metadata