gcp-to-aws

Warn

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic script generation and local execution to handle billing data analysis. In references/phases/discover/discover.md, it writes a temporary Python script (_extract_billing.py) to the local migration directory and executes it via the shell to parse and aggregate costs.
  • [COMMAND_EXECUTION]: The skill interacts with the host operating system to enhance user experience by executing shell commands. In references/phases/generate/generate-artifacts-report.md, it uses the open or xdg-open utility to automatically display the generated HTML migration report in the default system browser.
  • [DATA_EXFILTRATION]: The skill implements an optional feedback mechanism in references/phases/feedback/feedback.md that generates an anonymized JSON trace of the migration analysis. It provides this trace for manual submission to a survey URL hosted on a trusted Amazon domain (pulse.amazon). Although designed to be anonymized and manual, this represents a structured path for project metadata to leave the environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 10, 2026, 10:41 AM
Security Audit — agent-trust-hub — gcp-to-aws