aws-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture creates a surface for indirect prompt injection through the ingestion of external data and powerful cloud management capabilities.
  • Ingestion points: The agent reads reference documentation from references/CORE_CONCEPTS.md and is designed to execute AWS CLI commands which retrieve data from remote AWS resources (such as S3 object content, CloudWatch logs, or resource tags) that could be controlled by an external actor.
  • Boundary markers: The instructions lack explicit delimiters or specific instructions for the agent to ignore or sanitize embedded instructions within the data it retrieves from the AWS environment.
  • Capability inventory: The skill has broad execution capabilities via allowed tools (Bash), enabling it to modify cloud infrastructure, create or modify IAM resources, and write to the file system.
  • Sanitization: There is no evidence of input validation or output sanitization for data processed from external cloud services before it is used in subsequent agent reasoning steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:25 PM
Security Audit — agent-trust-hub — aws-expert