terraform-skill

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a purely educational and instructional resource providing best practices for Infrastructure as Code (IaC) using Terraform and OpenTofu. It emphasizes secure practices such as using AWS Secrets Manager instead of hardcoding credentials.
  • [EXTERNAL_DOWNLOADS]: The documentation includes reference templates for CI/CD pipelines that utilize well-known community tools. This includes fetching installation scripts from the official GitHub repositories of TFLint (terraform-linters) and Trivy (aquasecurity). These are standard practices for the described workflows and target reputable sources.
  • [REMOTE_CODE_EXECUTION]: While the documentation contains shell commands for installing tools via curl-to-bash patterns, these are provided as static examples for the user's own CI/CD configuration and are not executed by the agent or the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 01:10 PM