aws-billing-and-cost-management
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill mandates the use of generated Python scripts for all arithmetic operations (sums, percentages, averages) to prevent common LLM calculation errors. While this involves runtime script generation, it is explicitly instructed as a reliability measure for cost analysis.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from AWS API responses, including resource tags, names, and usage types. This ingestion occurs across all provided reference files during cost audits and resource optimization tasks. The skill identifies capabilities such as Python script execution and AWS CLI usage, but lacks instructions for explicit sanitization or boundary markers when interpolating this external data into the agent's context.
Audit Metadata