aws-billing

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell script (get_billing_aws.sh) containing functions that execute authorized AWS CLI commands such as aws ce, aws sts, and aws organizations. These are used appropriately to fetch billing data and account metadata for the user's reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on external data retrieved from AWS APIs, creating a potential surface for indirect injection. However, this is the intended functionality, and the skill includes extensive 'Anti-Hallucination' rules and structured output formats to ensure the agent processes the data safely.
  • Ingestion points: Billing data and account lists fetched from AWS services into the script environment.
  • Boundary markers: The SKILL.md defines a structured report format with clear headers to encapsulate the agent's findings.
  • Capability inventory: Shell execution for CLI tools and Python/Awk for data processing are present in get_billing_aws.sh.
  • Sanitization: The skill uses python3 -c for precise JSON parsing and awk to extract numeric fields, avoiding the risk of directly interpolating raw API strings into high-privilege prompts.
  • [DYNAMIC_EXECUTION]: The helper script uses short Python one-liners (python3 -c) to perform calculations such as mean daily cost and Z-score anomaly detection. These scripts are static templates used for local data processing and do not involve remote code execution or untrusted source code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — aws-billing