iam-departures-aws

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for automated identity remediation, mapping to MITRE ATT&CK (T1078.004) and CIS Controls (v8 6.2).
  • [PROMPT_INJECTION]: No attempts to override agent constraints or bypass safety guidelines were found. The instructional language is focused on operational safety and compliance.
  • [DATA_EXFILTRATION]: All data flows are consistent with the documented purpose. Manifests and audit logs are stored in user-controlled S3 buckets with KMS encryption.
  • [EXTERNAL_DOWNLOADS]: Dependencies are restricted to well-known, official SDKs from trusted organizations (AWS, Microsoft, Google, Snowflake, Databricks).
  • [COMMAND_EXECUTION]: No unauthorized shell command execution was detected. The skill uses official cloud SDKs for remediation logic and provides standard IaC templates for deployment.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly utilizes environment variables and provides guidance on integrating with secure secrets management services.
  • [SAFE]: Implements a dedicated security module to protect critical accounts, using both code-level assertions and IAM deny policies to prevent deletion of root or emergency users.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — iam-departures-aws