aws-serverless-eda
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard architectural guidelines for AWS services including Lambda, DynamoDB, and Step Functions. All code examples follow industry best practices for serverless development.
- [DATA_EXPOSURE]: The skill correctly recommends using environment variables for configuration (e.g.,
process.env.BUCKET_NAME) rather than hardcoding sensitive resource identifiers, which is a recognized security best practice. - [INDIRECT_PROMPT_INJECTION]: While the skill interacts with AWS MCP tools to fetch documentation and state, it does not ingest untrusted user data in a way that suggests a vulnerability to indirect injection. The risk is minimized by the instructional nature of the skill.
Audit Metadata