scoutsuite
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the legitimate
scoutcommand-line utility for cloud environment auditing. The commands provided are standard for security assessments and are used to gather configuration metadata from specified cloud providers (AWS, Azure, GCP). - [DATA_EXPOSURE_AND_EXFILTRATION]: While the tool is designed to collect cloud inventory and risk data, the instructions explicitly mandate that collection stay within approved account boundaries and that output reports be protected as sensitive evidence. No patterns of unauthorized exfiltration to external domains were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface where it ingests cloud metadata (e.g., service names, resource tags) that could theoretically contain malicious instructions. However, the risk is mitigated as the skill focuses on producing structured configuration reports rather than performing autonomous high-privilege actions based on the ingested data.
Audit Metadata