tf-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [Command Execution]: The skill includes a Python script (
validate-terraform-policy.py) designed to be executed by the agent to validate Terraform configurations. The test suite (test_validate_terraform_policy.py) also utilizessubprocess.runto invoke this validator against fixtures. These executions are restricted to the skill's own scripts and hardcoded test data, representing standard functional behavior rather than a security risk. - [Indirect Prompt Injection Surface]: The validator script processes external Terraform (
.tf) files. This represents an indirect prompt injection surface as the agent might ingest the resulting violation reports. However, the script implements a custom HCL lexer specifically designed to be robust against evasion techniques (such as hiding attributes within comments or strings), and the analysis is performed via static code logic rather than passing raw untrusted content directly into a prompt. This is considered a safe implementation. - [Dynamic Loading]: The test script uses
importlib.utilto dynamically load the validator script. This is necessary because the script's filename contains hyphens, making it non-importable through standard syntax. The loading path is statically determined relative to the test file's location, ensuring no untrusted paths are used. - [Safe Test Fixtures]: The repository contains multiple Terraform files in the
fixtures/directory that are intentionally insecure (e.g., public databases, wildcard IAM policies). These are clearly documented as non-compliant test data used for regression testing of the policy gate and do not pose a threat to the execution environment.
Audit Metadata