aws-strands

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to install external Python packages from an external registry to use the SDK.
  • Evidence: pip install strands-agents strands-agents-tools in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interface where an agent processes untrusted user data, which is a standard vector for indirect prompt injection.
  • Ingestion points: User input passed to the agent() function and the research tool documented in SKILL.md.
  • Boundary markers: None identified; the instructions do not specify delimiters to separate user data from system instructions.
  • Capability inventory: The agents possess the ability to invoke language models (AWS Bedrock) and execute Python functions defined with the @tool decorator.
  • Sanitization: No input validation or output filtering is demonstrated in the provided SDK implementation examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:28 PM
Security Audit — agent-trust-hub — aws-strands