investigate-blocker
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The workflow instructs the agent to include technical evidence such as 'configs' and 'logs' in GitHub issues and external markdown documents. This creates a risk of exposing sensitive environment variables, infrastructure details, or PII if the destination repository is public or shared with external parties without prior scrubbing.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. It ingests data from external AWS documentation and downloaded package source code to verify blockers. Maliciously crafted content in these external sources could influence the agent's behavior or findings.
- Ingestion points: AWS documentation via
aws___read_documentation, CloudWatch logs, and source code from downloaded Lambda packages. - Boundary markers: None identified in the prompt instructions to isolate untrusted data.
- Capability inventory: Uses
execute_bash(curl, unzip, grep, aws), creates GitHub issues, and writes local files in theDocs/directory. - Sanitization: No specific sanitization or filtering steps are defined for the data extracted from logs or documentation before it is included in escalation artifacts.
- [COMMAND_EXECUTION]: The skill relies on shell command execution to perform its primary function, including downloading code from AWS (
aws lambda get-function) and inspecting package contents. While the use of well-known services like AWS for downloads is standard, the broad use ofexecute_bashfor arbitrary file inspection and networking represents a high-privilege surface area.
Audit Metadata