coordinating-multi-space-devops-agent

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by instructing the agent to bridge data between different environments. Specifically, Pattern B describes taking output from a 'knowledge' AgentSpace and including it directly as context in an 'investigation' payload for a 'production' AgentSpace.
  • Ingestion points: External data enters the context via aws_devops_agent__chat responses and local project files such as AGENTS.md or .claude/aws-agents-for-devsecops.md.
  • Boundary markers: Absent. The instructions do not mandate the use of delimiters, XML tags, or explicit 'ignore embedded instructions' warnings when the agent interpolates bridged data into tool arguments.
  • Capability inventory: The agent has access to sensitive operations including aws_devops_agent__investigate and aws_devops_agent__chat across multiple AWS account scopes.
  • Sanitization: Absent. There is no instruction to validate, filter, or escape the content retrieved from one space before passing it to another.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 04:00 PM
Security Audit — agent-trust-hub — coordinating-multi-space-devops-agent