aws-fis-experiment-execute

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's design includes a surface for indirect prompt injection as it processes data from external sources that may be influenced by an attacker.
  • Ingestion points: The skill reads configuration from a local README.md and cfn-template.yaml, processes AWS API responses (from FIS and CloudFormation), and ingests application logs via the app-service-log-analysis sub-skill.
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded commands when processing these inputs.
  • Capability inventory: The skill has extensive capabilities, including executing AWS CLI commands (aws fis, aws cloudformation, aws logs), kubectl operations, and writing local files to the filesystem.
  • Sanitization: While the skill uses structural extraction tools like grep and jq, it lacks explicit instructions to sanitize or escape data extracted from logs or API outputs before using them in further logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 02:32 AM
Security Audit — agent-trust-hub — aws-fis-experiment-execute