iam-departures-aws
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices for automated identity remediation, mapping to MITRE ATT&CK (T1078.004) and CIS Controls (v8 6.2).
- [PROMPT_INJECTION]: No attempts to override agent constraints or bypass safety guidelines were found. The instructional language is focused on operational safety and compliance.
- [DATA_EXFILTRATION]: All data flows are consistent with the documented purpose. Manifests and audit logs are stored in user-controlled S3 buckets with KMS encryption.
- [EXTERNAL_DOWNLOADS]: Dependencies are restricted to well-known, official SDKs from trusted organizations (AWS, Microsoft, Google, Snowflake, Databricks).
- [COMMAND_EXECUTION]: No unauthorized shell command execution was detected. The skill uses official cloud SDKs for remediation logic and provides standard IaC templates for deployment.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly utilizes environment variables and provides guidance on integrating with secure secrets management services.
- [SAFE]: Implements a dedicated security module to protect critical accounts, using both code-level assertions and IAM deny policies to prevent deletion of root or emergency users.
Audit Metadata