aws
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided infrastructure-as-code and IAM policies, constituting an ingestion surface for untrusted data.\n
- Ingestion points: Workflows for reviewing IAM policies (
review-an-iam-policy-or-role), designing serverless applications (design-or-review-a-serverless-application), and recovering stacks (recover-a-stuck-or-failed-stack) ingest external files for analysis.\n - Boundary markers: The instructions do not define formal boundary markers or instructions to ignore embedded commands within the analyzed templates, though they emphasize offline simulation of policies.\n
- Capability inventory: The execution environment provides high-privilege tools such as the
awsCLI (v2),cfn-lint, andsamCLI, which could be targeted by instructions embedded in analyzed templates.\n - Sanitization: No specific sanitization, validation, or escaping logic for external content is described in the skill's core instructions.
Audit Metadata