source-s3-select

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Python scripts to interact with AWS S3 using the Boto3 library. It implements validation for the S3 Select SQL expressions to ensure they are restricted to read-only SELECT statements and do not contain multiple statements.
  • [EXTERNAL_DOWNLOADS]: The skill references and interacts with Amazon S3, which is a well-known technology service. Network egress is explicitly restricted to *.amazonaws.com in the configuration.
  • [CREDENTIALS_UNSAFE]: The skill follows secure practices for credential management by utilizing the standard AWS SDK credential chain (environment variables like AWS_ACCESS_KEY_ID). No hardcoded secrets were found in the codebase.
  • [DATA_EXFILTRATION]: While the skill reads data from S3, the data flow is intended for downstream agent consumption via stdout. The egress is limited to legitimate AWS endpoints, presenting no unauthorized exfiltration risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — source-s3-select