aws-sso-refresh
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to guide the agent in handling AWS SSO authentication errors by invoking a refresh tool.
- [DATA_EXPOSURE]: The skill mentions searching for
AWS_PROFILEinformation within local configuration files (e.g.,.mcp.json,~/.aws/amazonq/mcp.json). This is a legitimate operation for an authentication utility and does not involve exfiltrating secrets. - [REMOTE_CODE_EXECUTION]: No patterns for remote code execution, package installation, or shell script downloads were detected.
- [PROMPT_INJECTION]: The instructions do not contain attempts to override agent safety guidelines, bypass constraints, or extract system prompts.
- [COMMAND_EXECUTION]: The skill does not instruct the agent to execute arbitrary shell commands or acquire elevated privileges.
Audit Metadata