infra-iac-terraform

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or examples.
  • [EXTERNAL_DOWNLOADS]: The skill correctly references official and well-known providers and modules, such as the HashiCorp AWS provider and the community-verified AWS VPC module from the Terraform Registry. It provides instructions on pinning versions to ensure reproducibility and supply chain security.
  • [DATA_EXFILTRATION]: The instructions include explicit, repeated warnings against storing secrets in Terraform state or configuration files. It correctly recommends using environment variables or dedicated secret management services (like AWS Secrets Manager or HashiCorp Vault) to handle sensitive data safely.
  • [COMMAND_EXECUTION]: The CLI cheat sheet and patterns focus on standard, safe Terraform/OpenTofu workflows (init, plan, apply, fmt, validate) intended for infrastructure management.
  • [PROMPT_INJECTION]: The skill does not contain any instructions that attempt to override agent behavior, bypass safety guidelines, or extract system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 02:34 AM
Security Audit — agent-trust-hub — infra-iac-terraform