cloud-expense-management

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from AWS documentation and CloudWatch logs, which presents a surface for indirect prompt injection.
  • Ingestion points: Tools such as mcp__aws-mcp__aws___search_documentation, mcp__aws-mcp__aws___read_documentation, and general CloudWatch log monitoring referenced in references/operations-patterns.md.
  • Boundary markers: The instructions do not provide explicit delimiters or warnings to ignore instructions that might be contained within the logs or documentation retrieved.
  • Capability inventory: The skill provides access to AWS management, cost analysis, and security assessment tools via multiple MCP servers (Billing, Pricing, Cost Explorer, CloudWatch, etc.).
  • Sanitization: There are no documented procedures for sanitizing, validating, or escaping external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — cloud-expense-management