aws-strands
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the user to install external Python packages from an external registry to use the SDK.
- Evidence:
pip install strands-agents strands-agents-toolsinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill defines an interface where an agent processes untrusted user data, which is a standard vector for indirect prompt injection.
- Ingestion points: User input passed to the
agent()function and theresearchtool documented inSKILL.md. - Boundary markers: None identified; the instructions do not specify delimiters to separate user data from system instructions.
- Capability inventory: The agents possess the ability to invoke language models (AWS Bedrock) and execute Python functions defined with the
@tooldecorator. - Sanitization: No input validation or output filtering is demonstrated in the provided SDK implementation examples.
Audit Metadata