aws-serverless-eda

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard architectural guidelines for AWS services including Lambda, DynamoDB, and Step Functions. All code examples follow industry best practices for serverless development.
  • [DATA_EXPOSURE]: The skill correctly recommends using environment variables for configuration (e.g., process.env.BUCKET_NAME) rather than hardcoding sensitive resource identifiers, which is a recognized security best practice.
  • [INDIRECT_PROMPT_INJECTION]: While the skill interacts with AWS MCP tools to fetch documentation and state, it does not ingest untrusted user data in a way that suggests a vulnerability to indirect injection. The risk is minimized by the instructional nature of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:39 AM
Security Audit — agent-trust-hub — aws-serverless-eda