awsclaw-iam

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a wide range of AWS IAM operations through the IAMTool, enabling the agent to create, modify, and delete roles, users, and policies. These capabilities are consistent with its stated purpose of cloud infrastructure management.
  • [DATA_EXFILTRATION]: The skill can access sensitive security data, including AWS credential reports and MFA device configurations. This access is intended for security auditing and is performed within the agent's operational context without external exfiltration.
  • [PROMPT_INJECTION]: The skill processes untrusted data from the AWS environment, such as policy documents and resource tags, which creates an indirect prompt injection surface. However, no malicious payloads or override instructions were detected in the static analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 08:11 PM