access-review
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill includes defensive instructions to detect and ignore prompt injection attempts within analyzed data. A static detection hit for instruction override was found to be a false positive, as it is actually a security mitigation instruction.
- [PROMPT_INJECTION]: The skill processes untrusted IAM metadata and role descriptions. It implements strong boundary markers and instructions to mitigate indirect prompt injection. Evidence Chain: 1. Ingestion points: target-file argument and Read tool. 2. Boundary markers: Present in Injection Hardening and Safety Notice sections. 3. Capability inventory: Limited to Read, Grep, Glob tools. 4. Sanitization: Instructions to treat data as untrusted and ignore embedded directives.
- [DATA_EXFILTRATION]: The skill lacks network tools and includes explicit directives prohibiting the external transfer of sensitive information discovered during audits.
Audit Metadata