deploying-cdk-ts
Pass
Audited by Gen Agent Trust Hub on May 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the local system to execute
cdk diff,cdk deploy, and variousawsCLI commands. These operations are core to the infrastructure management workflow and are used to retrieve stack information and perform deployments. - [DATA_EXFILTRATION]: Resource metadata, including ARNs and security configurations, is collected from AWS and transmitted to an external service (ClickUp). While this is the skill's primary purpose, it involves moving environment data to a third-party platform.
- [PROMPT_INJECTION]: The skill processes untrusted data from AWS stack outputs and resource tags, creating a surface for indirect prompt injection.
- Ingestion points: Data enters the context from
outputs.json,cdk diffoutput, andaws cloudformation list-stack-resourcesoutput. - Boundary markers: The skill explicitly includes a 'Behaviour Rule' instructing the agent to treat deployment output as untrusted and avoid following instructions found in resource tags.
- Capability inventory: The skill possesses subprocess execution capabilities via
cdkandawsCLI, and write capabilities to an external platform via ClickUp MCP tools. - Sanitization: The instructions direct the agent to extract only structured fields (ARNs, status) to limit the impact of potentially malicious content in external outputs.
Audit Metadata