cost-aws

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection as it processes data retrieved from external AWS documentation and pricing endpoints.
  • Ingestion points: Data is ingested via documentation reading tools and a curl request to the official AWS pricing API.
  • Boundary markers: The skill instructions do not specify any delimiters or instructions for the agent to ignore or isolate potential commands embedded in the retrieved external data.
  • Capability inventory: The skill utilizes the aws CLI for reading account costs and managing monitors, and it includes commands for installing external packages via uvx, brew, or pip.
  • Sanitization: There is no evidence of validation or sanitization of the content fetched from external documentation or APIs before it is used by the agent context.
  • [COMMAND_EXECUTION]: The skill uses the AWS CLI to interact with the user's account, including reading billing data and performing management actions.
  • Evidence: It instructs the agent to use aws ce get-cost-and-usage to access billing info and aws ce create-anomaly-monitor to perform account-level operations by creating monitoring resources.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing various tools and fetching remote data.
  • Evidence: It suggests installing the mcp-server-aws and mcp-server-aws-docs packages via uvx, and the awscli tool via brew or pip. Additionally, it fetches a pricing JSON file from pricing.us-east-1.amazonaws.com using curl.
  • [DATA_EXFILTRATION]: The skill is designed to access and process sensitive financial and usage data from the user's AWS account.
  • Evidence: The use of Cost Explorer (aws ce) commands provides the agent with access to granular account billing data, which is necessary for the skill's primary function but involves handling sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 07:44 AM
Security Audit — agent-trust-hub — cost-aws