cost-aws
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection as it processes data retrieved from external AWS documentation and pricing endpoints.
- Ingestion points: Data is ingested via documentation reading tools and a
curlrequest to the official AWS pricing API. - Boundary markers: The skill instructions do not specify any delimiters or instructions for the agent to ignore or isolate potential commands embedded in the retrieved external data.
- Capability inventory: The skill utilizes the
awsCLI for reading account costs and managing monitors, and it includes commands for installing external packages viauvx,brew, orpip. - Sanitization: There is no evidence of validation or sanitization of the content fetched from external documentation or APIs before it is used by the agent context.
- [COMMAND_EXECUTION]: The skill uses the AWS CLI to interact with the user's account, including reading billing data and performing management actions.
- Evidence: It instructs the agent to use
aws ce get-cost-and-usageto access billing info andaws ce create-anomaly-monitorto perform account-level operations by creating monitoring resources. - [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing various tools and fetching remote data.
- Evidence: It suggests installing the
mcp-server-awsandmcp-server-aws-docspackages viauvx, and theawsclitool viabreworpip. Additionally, it fetches a pricing JSON file frompricing.us-east-1.amazonaws.comusingcurl. - [DATA_EXFILTRATION]: The skill is designed to access and process sensitive financial and usage data from the user's AWS account.
- Evidence: The use of Cost Explorer (
aws ce) commands provides the agent with access to granular account billing data, which is necessary for the skill's primary function but involves handling sensitive information.
Audit Metadata