aws-best-practice-research
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data that could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Documentation is fetched from external sources via
aws___search_documentationandaws___read_documentation. Resource configuration (tags, metadata) is fetched from the user's AWS account via theawsCLI. - Boundary markers: The instructions do not define explicit boundary markers or delimiters when interpolating documentation content into the agent's context.
- Capability inventory: The skill has the ability to execute shell commands (
source,awsCLI) and write to the local file system. - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external documentation before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill uses shell commands to perform live resource assessments and manage environment variables.
- Evidence: In
SKILL.mdStep 8.1, the agent is instructed to usesource <credential-file-path>to load environment variables from a user-specified file. - Evidence:
references/assessment-workflow.mddefines numerous AWS CLI commands (e.g.,aws elasticache describe-replication-groups,aws rds describe-db-instances) that are executed at runtime to gather resource configurations.
Audit Metadata