deploying-cdk-ts

Pass

Audited by Gen Agent Trust Hub on May 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local system to execute cdk diff, cdk deploy, and various aws CLI commands. These operations are core to the infrastructure management workflow and are used to retrieve stack information and perform deployments.
  • [DATA_EXFILTRATION]: Resource metadata, including ARNs and security configurations, is collected from AWS and transmitted to an external service (ClickUp). While this is the skill's primary purpose, it involves moving environment data to a third-party platform.
  • [PROMPT_INJECTION]: The skill processes untrusted data from AWS stack outputs and resource tags, creating a surface for indirect prompt injection.
  • Ingestion points: Data enters the context from outputs.json, cdk diff output, and aws cloudformation list-stack-resources output.
  • Boundary markers: The skill explicitly includes a 'Behaviour Rule' instructing the agent to treat deployment output as untrusted and avoid following instructions found in resource tags.
  • Capability inventory: The skill possesses subprocess execution capabilities via cdk and aws CLI, and write capabilities to an external platform via ClickUp MCP tools.
  • Sanitization: The instructions direct the agent to extract only structured fields (ARNs, status) to limit the impact of potentially malicious content in external outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
May 25, 2026, 02:15 PM
Security Audit — agent-trust-hub — deploying-cdk-ts