awsflow-ec2
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by retrieving data from the AWS environment that can contain malicious instructions while possessing broad administrative capabilities. * Ingestion points: Commands like
DescribeInstancesandGetConsoleOutputfetch data from the cloud environment that may be user-controlled. * Boundary markers: The instructions lack delimiters or specific warnings to isolate untrusted AWS data from the prompt context. * Capability inventory: The skill has high-impact management capabilities such asTerminateInstances,DeleteVpc, and security group modification. * Sanitization: No logic is present in the skill definition to validate or sanitize data retrieved from the API before it is processed by the agent. - [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The functionality is consistent with the stated purpose of cloud resource management.
Audit Metadata