aws-well-architected-review
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes repository configuration files and generates external GitHub issues, which presents a surface for indirect prompt injection. \n- Ingestion points: Repository IaC files including Terraform, CloudFormation, and CDK source files are scanned in Step 2. \n- Boundary markers: A mandatory user confirmation step is included in Step 5 before the agent creates any GitHub issues. \n- Capability inventory: The skill utilizes the GitHub MCP server to create issues and EPICs based on detected findings. \n- Sanitization: No specific input validation or sanitization of file content is described in the workflow.\n- [EXTERNAL_DOWNLOADS]: The skill downloads reference architecture guidelines from official AWS documentation. \n- The downloads originate from docs.aws.amazon.com, which is a well-known and expected source for this utility.
Audit Metadata