awsflow-ec2

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by retrieving data from the AWS environment that can contain malicious instructions while possessing broad administrative capabilities. * Ingestion points: Commands like DescribeInstances and GetConsoleOutput fetch data from the cloud environment that may be user-controlled. * Boundary markers: The instructions lack delimiters or specific warnings to isolate untrusted AWS data from the prompt context. * Capability inventory: The skill has high-impact management capabilities such as TerminateInstances, DeleteVpc, and security group modification. * Sanitization: No logic is present in the skill definition to validate or sanitize data retrieved from the API before it is processed by the agent.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The functionality is consistent with the stated purpose of cloud resource management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 11:07 AM
Security Audit — agent-trust-hub — awsflow-ec2