aws-secrets-inspector-expert

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation-only file providing guidance on interpreting security posture data for AWS Secrets Manager. It contains no executable scripts, shell commands, or tool definitions.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions reference sensitive local paths used for AWS credentials (/.aws/credentials) and secret storage (/.config/claude-grc/secrets/). These references are strictly for diagnostic and operational documentation purposes, explaining the security guarantees of the associated tool (such as path validation and file permissions) rather than instructing the agent to expose or exfiltrate data.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and interpret output from an external AWS connector, creating a surface for indirect prompt injection. While malicious data within AWS resource policies could attempt to influence the agent's interpretation, the skill provides specific, structured logic for the AI to follow, and the skill itself does not have access to sensitive tools that could be abused through such an injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:06 AM
Security Audit — agent-trust-hub — aws-secrets-inspector-expert