source-s3-select
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Python scripts to interact with AWS S3 using the Boto3 library. It implements validation for the S3 Select SQL expressions to ensure they are restricted to read-only
SELECTstatements and do not contain multiple statements. - [EXTERNAL_DOWNLOADS]: The skill references and interacts with Amazon S3, which is a well-known technology service. Network egress is explicitly restricted to
*.amazonaws.comin the configuration. - [CREDENTIALS_UNSAFE]: The skill follows secure practices for credential management by utilizing the standard AWS SDK credential chain (environment variables like
AWS_ACCESS_KEY_ID). No hardcoded secrets were found in the codebase. - [DATA_EXFILTRATION]: While the skill reads data from S3, the data flow is intended for downstream agent consumption via stdout. The egress is limited to legitimate AWS endpoints, presenting no unauthorized exfiltration risk.
Audit Metadata