gcp-aws-migrate

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the uvx command to download and run the aws-pricing-mcp-server package. This package is maintained by the awslabs organization, which is a well-known and trusted source for cloud tooling.\n- [COMMAND_EXECUTION]: The tool executes the uvx command to initialize the pricing server during the cost estimation phase of the migration. This is an expected operation for the skill's stated purpose.\n- [PROMPT_INJECTION]: The skill processes user-supplied data from external environments, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: The skill is instructed to scan Terraform .tf files, application source code with GCP SDK imports, and billing exports (CSV or JSON) as defined in the input requirements.\n
  • Boundary markers: The instructions do not specify any delimiters or warnings to the agent to disregard instructions that may be embedded within the processed migration data.\n
  • Capability inventory: The skill has the capability to generate executable Terraform configurations, migration scripts, and architecture documentation based on its analysis.\n
  • Sanitization: No input validation or sanitization mechanisms are described for the content of the files ingested by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:29 AM
Security Audit — agent-trust-hub — gcp-aws-migrate