Back to skill

Security audit

Aws Graph Agent Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent AWS Bedrock AgentCore/LangGraph deployment guide, with cloud-impacting commands disclosed as part of its stated purpose.

Before installing or using it, be prepared for the agent to run package installs and AWS AgentCore CLI commands. Confirm the target AWS account, region, credentials, and expected costs before deployment, and explicitly approve cleanup/destruction actions when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill includes deployment and destruction commands that can change cloud state and incur or affect billing, but it does not place a prominent upfront warning before operational steps. In an agent context with exec capability, users may trigger `launch` or `destroy` without fully understanding the side effects on infrastructure and costs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.