iam-review

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains phrases often associated with prompt injection, such as "ignore previous instructions." A technical review confirms these are implemented as defensive controls. The instructions explicitly direct the agent to identify these patterns as malicious findings within the analyzed data rather than obeying them.
  • [DATA_EXFILTRATION]: The skill addresses the risk of data exposure by explicitly forbidding the exfiltration of credentials, access keys, or secrets found during the IAM review. It mandates that such values be redacted or referenced generically in the output.
  • [SAFE]: The skill demonstrates high security maturity by establishing clear security boundaries and using a restricted toolset (Read, Grep, Glob). It treats all external configuration data as untrusted input and provides structured frameworks (NIST, CIS) for assessment without introducing executable code or network dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — iam-review