aws-serverless

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for AWS Lambda handlers that ingest untrusted data from external sources such as API Gateway and SQS queues. This represents a standard attack surface for indirect prompt injection if the processed data contains malicious instructions targeting downstream LLM processing.
  • Ingestion points: Handlers in SKILL.md (e.g., line 33 and line 142) parse input from event.body and record.body.
  • Boundary markers: The provided code snippets do not include specific boundary markers or instructions to ignore embedded commands, which is expected for generic boilerplate templates.
  • Capability inventory: The skill includes code to interact with AWS services, specifically reading and writing to DynamoDB using official AWS SDKs.
  • Sanitization: The patterns demonstrate standard JSON parsing but do not include explicit sanitization or validation logic, leaving that to the implementer.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — aws-serverless