aws-cost-operations

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to process untrusted external data.
  • Ingestion points: The skill uses MCP tools to ingest data from AWS Documentation, CloudWatch logs, and CloudTrail audit trails (e.g., mcp__aws-mcp__aws___search_documentation, mcp__*cloudwatch*).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat external tool outputs as untrusted or to ignore embedded instructions within that data.
  • Capability inventory: The skill instructs the agent to analyze this ingested data for security assessments, troubleshooting, and cost estimation. It does not perform autonomous file writes or shell command execution based on this data.
  • Sanitization: No explicit sanitization or validation of the data retrieved via MCP tools is mentioned in the instructions.
  • [SAFE]: The skill's primary purpose is educational and operational guidance. It provides valid AWS Cloud Development Kit (CDK) code snippets as examples and follows standard industry practices for cloud resource management. All external references are local or standard documentation links.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 05:03 AM
Security Audit — agent-trust-hub — aws-cost-operations