cloud-security-automation
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a legitimate and secure workflow for multi-cloud security posture management. It explicitly instructs the agent to use read-only credentials, avoid data exfiltration, and utilize well-known security tools like Prowler, Checkov, and Steampipe.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to ingest and process external data, creating a theoretical attack surface for indirect prompt injection.
- Ingestion points: Cloud configuration data retrieved via provider APIs (AWS, Azure, GCP) and Infrastructure-as-Code (IaC) files provided for scanning.
- Boundary markers: The instructions lack specific delimiters or isolation markers to separate external data from the agent's core instructions.
- Capability inventory: The agent is authorized to generate remediation patches (IaC diffs), IAM policies, and response runbooks based on the data it analyzes.
- Sanitization: There are no explicit instructions provided to sanitize or validate the integrity of the data ingested from cloud environments or code repositories before processing.
Audit Metadata