pulumi-cdk-to-pulumi
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates the migration process by invoking several command-line utilities to interact with AWS and local files.
- It uses
npx cdk synth --quietto generate the CloudFormation assembly needed for conversion. - It utilizes
jqto extract stack metadata fromcdk.out/manifest.jsonand asset information from*.assets.jsonfiles. - It performs discovery of existing cloud resources using
aws cloudformation list-stack-resources. - It manages Pulumi configuration and performs previews using the
pulumiCLI. - [DYNAMIC_EXECUTION]: The migration workflow involves installing and running specialized Pulumi plugins and executing user-controlled CDK logic.
- The instructions specify installing
cdk2pulumiandcdk-importerplugins viapulumi plugin install. - The conversion process relies on
pulumi plugin run, which executes binary or script-based tool logic. - Running
cdk synthexecutes the logic defined within the CDK application source code. - [INDIRECT_PROMPT_INJECTION]: The skill processes external project artifacts that could be manipulated to influence downstream command execution.
- Ingestion points: The skill reads
cdk.out/manifest.json,cdk.out/*.assets.json, and project configuration files likecdk.jsonorpackage.json. - Boundary markers: No explicit delimitation or sanitization instructions are provided to the agent for handling values parsed from these files.
- Capability inventory: The agent has capabilities to execute shell commands (
aws,cdk,pulumi,jq) and perform network fetches from Pulumi documentation sites. - Sanitization: There is a lack of explicit validation for stack names, regions, or asset identifiers retrieved from manifests before they are used as arguments in shell commands.
Audit Metadata