managed-ingestion-service
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses legitimate AWS CLI tools (such as
aws sts,aws opensearch, andaws osis) to validate service status and manage resource lifecycle. All commands are standard for infrastructure-as-code or manual cloud management tasks. - [DATA_EXFILTRATION]: Instructions are provided to upload document chunks to Amazon S3. This operation moves data into the user's own cloud environment and is the intended primary function of the ingestion skill.
- [COMMAND_EXECUTION]: The
iam-setup.mdfile contains templates for creating IAM roles and attaching policies. While these involve privileged operations, the permissions (e.g., S3 read and OpenSearch write access) are correctly scoped to the operational requirements of the OpenSearch Ingestion Service. - [EXTERNAL_DOWNLOADS]: The skill references an official contact email at
amazon.comfor private beta enrollment. This is a static reference to a well-known service domain and does not involve automated or suspicious downloads.
Audit Metadata