Aws Compliance Checker
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes multiple shell scripts and Python code snippets that execute AWS CLI commands (e.g.,
aws iam,aws ec2,aws cloudtrail) and utilize theboto3library to audit AWS account configurations for security benchmarks. - [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from external AWS APIs to perform its analysis, which represents a potential ingestion surface for indirect prompt injection if account resource metadata were manipulated by an adversary.
- Ingestion points: Outputs from AWS CLI commands (e.g.,
aws iam get-credential-report,aws ec2 describe-security-groups) in files likecis-iam-checks.sh,cis-logging-checks.sh,cis-networking-checks.sh, andpci-dss-checker.py. - Boundary markers: None; the scripts pipe raw output directly to processing tools like
awkandjq. - Capability inventory: Shell script execution, AWS CLI command invocation, and Python script execution.
- Sanitization: Data is filtered and parsed using
awkfor CSV reports,jqfor JSON payloads, and standard Python object manipulation.
Audit Metadata