cost-optimization

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): The skill contains standard instructional language focused on its primary purpose. No patterns of role-play, jailbreak, or safety filter bypass were detected.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, API keys, or sensitive file paths (e.g., ~/.aws/credentials) are present. The examples use generic placeholders like 'ami-12345678' and 'team@example.com'.
  • [Obfuscation] (SAFE): No Base64, zero-width characters, or encoded strings were found in the text or code snippets.
  • [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill does not perform any remote package installations or script executions (e.g., curl | bash). All referenced files are local to the skill structure.
  • [Command Execution] (SAFE): There are no system commands, shell executions, or subprocess spawns within the documentation or HCL snippets.
  • [Indirect Prompt Injection] (SAFE): The skill is a static documentation resource. It does not ingest untrusted external data at runtime into sensitive sinks, presenting no clear attack surface for indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:07 PM