cloud-finops
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides an extensive catalog of CLI command templates for major cloud providers, including AWS (e.g.,
aws ec2 describe-reserved-instances), Azure (e.g.,az vm deallocate), and Google Cloud (e.g.,gcloud compute disks list). It also provides SQL query templates for data analysis platforms like Amazon Athena, Azure Resource Graph (Kusto), and Google BigQuery. - [EXTERNAL_DOWNLOADS]: The documentation references and recommends several third-party tools for metering AI token usage and optimizing costs, such as
ccusage,tokview(token-viewer), andCodeBurn. It also links to official documentation and repositories from trusted organizations and well-known services including Anthropic, Google Cloud, Microsoft Azure, and the FinOps Foundation. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an analysis surface where the agent is instructed to ingest data from the user's cloud environment to perform diagnostics.
- Ingestion points: Untrusted data enters the context when the agent executes the provided CLI or SQL commands against the user's cloud infrastructure (e.g.,
SKILL.md,playbooks/aws-orphaned-ebs-volumes.md). - Boundary markers: The skill does not explicitly use delimiters or specialized instructions to distinguish tool output from internal instructions in the provided templates.
- Capability inventory: The skill suggests the use of cloud-native CLI tools and database query capabilities to retrieve metadata and billing records across multiple scripts and playbooks.
- Sanitization: The instructions focus on diagnostic reasoning and do not specify data sanitization or filtering for the retrieved cloud telemetry before processing.
Audit Metadata