managed-ingestion-service

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses legitimate AWS CLI tools (such as aws sts, aws opensearch, and aws osis) to validate service status and manage resource lifecycle. All commands are standard for infrastructure-as-code or manual cloud management tasks.
  • [DATA_EXFILTRATION]: Instructions are provided to upload document chunks to Amazon S3. This operation moves data into the user's own cloud environment and is the intended primary function of the ingestion skill.
  • [COMMAND_EXECUTION]: The iam-setup.md file contains templates for creating IAM roles and attaching policies. While these involve privileged operations, the permissions (e.g., S3 read and OpenSearch write access) are correctly scoped to the operational requirements of the OpenSearch Ingestion Service.
  • [EXTERNAL_DOWNLOADS]: The skill references an official contact email at amazon.com for private beta enrollment. This is a static reference to a well-known service domain and does not involve automated or suspicious downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 08:04 AM
Security Audit — agent-trust-hub — managed-ingestion-service