gcp-aws-migrate
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
uvxcommand to download and run theaws-pricing-mcp-serverpackage. This package is maintained by theawslabsorganization, which is a well-known and trusted source for cloud tooling.\n- [COMMAND_EXECUTION]: The tool executes theuvxcommand to initialize the pricing server during the cost estimation phase of the migration. This is an expected operation for the skill's stated purpose.\n- [PROMPT_INJECTION]: The skill processes user-supplied data from external environments, creating a potential surface for indirect prompt injection.\n - Ingestion points: The skill is instructed to scan Terraform .tf files, application source code with GCP SDK imports, and billing exports (CSV or JSON) as defined in the input requirements.\n
- Boundary markers: The instructions do not specify any delimiters or warnings to the agent to disregard instructions that may be embedded within the processed migration data.\n
- Capability inventory: The skill has the capability to generate executable Terraform configurations, migration scripts, and architecture documentation based on its analysis.\n
- Sanitization: No input validation or sanitization mechanisms are described for the content of the files ingested by the agent.
Audit Metadata