aws-best-practice-research

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data that could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Documentation is fetched from external sources via aws___search_documentation and aws___read_documentation. Resource configuration (tags, metadata) is fetched from the user's AWS account via the aws CLI.
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters when interpolating documentation content into the agent's context.
  • Capability inventory: The skill has the ability to execute shell commands (source, aws CLI) and write to the local file system.
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external documentation before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses shell commands to perform live resource assessments and manage environment variables.
  • Evidence: In SKILL.md Step 8.1, the agent is instructed to use source <credential-file-path> to load environment variables from a user-specified file.
  • Evidence: references/assessment-workflow.md defines numerous AWS CLI commands (e.g., aws elasticache describe-replication-groups, aws rds describe-db-instances) that are executed at runtime to gather resource configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 08:49 AM