Aws Secrets Rotation
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill demonstrates commands for reading sensitive local files, such as
~/.ssh/id_rsa, to upload them to AWS Secrets Manager. While this is a legitimate use case for the skill, accessing private keys is a sensitive operation that requires careful handling. - [INDIRECT_PROMPT_INJECTION]: The skill's audit and reporting scripts process data retrieved from AWS Secrets Manager and RDS APIs, creating a potential surface for indirect prompt injection if an attacker can control the metadata or content of the stored secrets.
- Ingestion points: Secret list data fetched via
client.list_secrets()and theaws secretsmanager list-secretsCLI command. - Boundary markers: The scripts do not use specific delimiters or instructions to prevent the agent from interpreting data within the secret fields as instructions.
- Capability inventory: The skill possesses the capability to execute shell commands, perform network requests via the
requestslibrary, and interact with databases usingpymysql. - Sanitization: The scripts rely on standard JSON parsing and do not implement additional sanitization or validation of the secret content.
- [COMMAND_EXECUTION]: The skill heavily utilizes the AWS CLI and custom scripts to manage cloud infrastructure and credentials, involving direct command execution to perform administrative tasks.
Audit Metadata