cloud-security-automation

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a legitimate and secure workflow for multi-cloud security posture management. It explicitly instructs the agent to use read-only credentials, avoid data exfiltration, and utilize well-known security tools like Prowler, Checkov, and Steampipe.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to ingest and process external data, creating a theoretical attack surface for indirect prompt injection.
  • Ingestion points: Cloud configuration data retrieved via provider APIs (AWS, Azure, GCP) and Infrastructure-as-Code (IaC) files provided for scanning.
  • Boundary markers: The instructions lack specific delimiters or isolation markers to separate external data from the agent's core instructions.
  • Capability inventory: The agent is authorized to generate remediation patches (IaC diffs), IAM policies, and response runbooks based on the data it analyzes.
  • Sanitization: There are no explicit instructions provided to sanitize or validate the integrity of the data ingested from cloud environments or code repositories before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 11:07 AM
Security Audit — agent-trust-hub — cloud-security-automation