Aws Compliance Checker

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes multiple shell scripts and Python code snippets that execute AWS CLI commands (e.g., aws iam, aws ec2, aws cloudtrail) and utilize the boto3 library to audit AWS account configurations for security benchmarks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from external AWS APIs to perform its analysis, which represents a potential ingestion surface for indirect prompt injection if account resource metadata were manipulated by an adversary.
  • Ingestion points: Outputs from AWS CLI commands (e.g., aws iam get-credential-report, aws ec2 describe-security-groups) in files like cis-iam-checks.sh, cis-logging-checks.sh, cis-networking-checks.sh, and pci-dss-checker.py.
  • Boundary markers: None; the scripts pipe raw output directly to processing tools like awk and jq.
  • Capability inventory: Shell script execution, AWS CLI command invocation, and Python script execution.
  • Sanitization: Data is filtered and parsed using awk for CSV reports, jq for JSON payloads, and standard Python object manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — Aws Compliance Checker