cloud-expense-management
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from AWS documentation and CloudWatch logs, which presents a surface for indirect prompt injection.
- Ingestion points: Tools such as mcp__aws-mcp__aws___search_documentation, mcp__aws-mcp__aws___read_documentation, and general CloudWatch log monitoring referenced in references/operations-patterns.md.
- Boundary markers: The instructions do not provide explicit delimiters or warnings to ignore instructions that might be contained within the logs or documentation retrieved.
- Capability inventory: The skill provides access to AWS management, cost analysis, and security assessment tools via multiple MCP servers (Billing, Pricing, Cost Explorer, CloudWatch, etc.).
- Sanitization: There are no documented procedures for sanitizing, validating, or escaping external content before it is processed by the agent.
Audit Metadata