aws-serverless

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection attempts. The instructions focus purely on AWS serverless development patterns without attempting to override agent behavior or safety guardrails.- [EXTERNAL_DOWNLOADS]: The skill references standard AWS SDKs (boto3, @aws-sdk/client-dynamodb). These are well-known, legitimate libraries for the stated purpose of the skill and do not originate from untrusted sources.- [DATA_EXFILTRATION]: No evidence of data exfiltration. The network operations described (DynamoDB and SQS interactions) are standard for AWS serverless applications and do not target suspicious or unknown external domains.- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The code samples correctly use environment variables (e.g., process.env.TABLE_NAME) and IAM policies for resource access, which is a recommended security practice.- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for processing external data (API Gateway events and SQS messages). While these are ingestion surfaces, they are standard for serverless handlers. The provided samples use standard JSON parsing, which is appropriate for the context. Evidence: 1. Ingestion points: event.body in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: DynamoDB read/write operations via official SDKs. 4. Sanitization: Standard JSON parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — aws-serverless