terraform-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to interact with various shell-based development and infrastructure tools as part of the standard engineering workflow.
  • Evidence includes the core lifecycle commands: terraform fmt, terraform validate, tflint, terraform plan, and terraform apply.
  • Additional commands for environment setup and testing are provided, such as pip install pre-commit, brew install tflint, go test (for Terratest suites), and opa eval for policy-as-code validation.
  • [EXTERNAL_DOWNLOADS]: The skill references standard external dependencies and repositories required for Terraform development and CI/CD pipelines.
  • Evidence includes the use of the Terraform Registry for module sourcing, Helm repositories for Kubernetes charts, and community-maintained Git repositories for linter rules and pre-commit hooks (e.g., github.com/antonbabenko/pre-commit-terraform).
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the processing of external infrastructure code and tool outputs.
  • Ingestion points: The agent analyzes HCL source files, Terraform plan JSON files, and the output of linters and security scanners (SKILL.md, references/testing.md).
  • Boundary markers: Absent; there are no specific instructions to the agent to treat ingested HCL or tool diagnostic output as untrusted data.
  • Capability inventory: The skill provides access to the shell for cloud resource management via terraform apply, software installation via pip/brew, and execution of custom test logic via go test (references/testing.md).
  • Sanitization: The skill does not outline specific sanitization procedures for data ingested from infrastructure code or external tool reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — terraform-engineer