aws-account-management

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes numerous AWS CLI commands for administrative and auditing tasks. This includes the command aws iam get-credential-report --output text --query Content | base64 -d, which decodes and displays an account-wide credential audit report containing metadata about user access and MFA status.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection due to its interaction with external cloud data.
  • Ingestion points: Data is ingested from AWS APIs through commands such as aws iam list-users and via Python's boto3 client in SKILL.md.
  • Boundary markers: The skill does not implement boundary markers or instructions for the agent to ignore potentially malicious content embedded in AWS resource metadata.
  • Capability inventory: The skill possesses high-privilege capabilities including organization management (aws organizations create-account), identity management (aws sso-admin create-permission-set), and policy configuration.
  • Sanitization: There is no evidence of data sanitization or validation performed on the retrieved AWS identifiers or report data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:05 PM
Security Audit — agent-trust-hub — aws-account-management