aws-roles-trust-policies-allow
Do any IAM roles have trust policies that allow principals from other accounts without requiring MFA or an External ID?
Task 39 of 127 · ISPM-Enterprise-SQL@v1
The line above is the complete prompt. An agent answers it strictly from the frozen world’s own configurations and relationships — the answer key is not in its workspace.
How this task is classified.
Theme
Privilege & exposure
privilege-exposureScope
Platform-level
single-platformSystems spanned
1 system
Platforms
AWS
Complexity
Easy
How it is graded.
There is no per-task rule. Every task in this contract is graded on the same 6 judged dimensions, over ispm-crossvendor-v1, with the panel’s consensus deciding each grade.
Run this task alone.
shell
$ osb run ISPM-Enterprise-SQL@v1 default \--tasks aws-roles-trust-policies-allow