serverless-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The code examples in
references/EXAMPLES.mddemonstrate processing data from untrusted external sources (API Gateway, S3, SQS, and DynamoDB Streams) without incorporating boundary markers or sanitization logic. This creates a vulnerability surface where malicious payloads in external data could influence the behavior of the processing logic. - Ingestion points:
create_order_handler(API body),s3_event_handler(S3 object content),sqs_batch_handler(SQS message body), andprocess_order_stream_handler(DynamoDB record data) inreferences/EXAMPLES.md. - Boundary markers: None present in the code examples to delimit external data from instructions.
- Capability inventory: The skill's examples include capabilities to write to S3, write to DynamoDB, publish to SNS, and invoke other Lambda functions.
- Sanitization: No validation or sanitization is applied to the data retrieved from external sources beyond basic JSON parsing.
- [PRIVILEGE_ESCALATION]: The Serverless Framework configuration in
references/EXAMPLES.mddefines IAM policy statements that use wildcards (*) for thelambda:InvokeFunctionaction. This grants the service permissions to invoke any Lambda function within the account and region, which exceeds the principle of least privilege required for the described architecture.
Audit Metadata