aws-agentcore

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration specifies downloading and executing the awslabs.agentcore-mcp-server package via uvx. This is the standard delivery method for the official AWS-labs toolset described in the skill and originates from a well-known service infrastructure.- [INDIRECT_PROMPT_INJECTION]: The skill features tools that ingest data from external documentation sources, which represents a potential attack surface. However, this is inherent to the skill's purpose and no malicious usage was found.
  • Ingestion points: search_agentcore_docs and fetch_agentcore_doc tools defined in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Includes system management tools like manage_agentcore_runtime and manage_agentcore_gateway.
  • Sanitization: Absent.- [SAFE]: No evidence of direct prompt injection, credential exfiltration, obfuscation, or persistence mechanisms was detected. The instructions follow standard AWS authentication and development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:29 AM
Security Audit — agent-trust-hub — aws-agentcore