Aws Iam Best Practices

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains multiple Bash and Python code blocks that utilize the official AWS CLI and boto3 SDK. These commands are used to query IAM resources, such as listing policies, checking user MFA status, and auditing access key ages.
  • [DATA_EXPOSURE]: The skill accesses AWS IAM configuration data, which is necessary for its stated purpose of security auditing. Access is limited to standard IAM metadata, and no patterns for exfiltrating this data to external or untrusted domains were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes logic to process IAM policy documents (JSON). The risk is minimal as the scripts perform direct string matching or programmatic parsing (e.g., checking for wildcard actions) rather than passing raw untrusted data directly into an LLM prompt for interpretation.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and tools from Amazon Web Services (AWS), which is a well-known and trusted service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — Aws Iam Best Practices