terraform-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate utility for infrastructure-as-code (IaC) security auditing and module quality analysis. The included scripts perform static analysis of local files and do not exhibit any malicious patterns or perform network communication.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Terraform files, which represents a potential surface for indirect prompt injection if the analyzed files contain malicious instructions. However, the risk is low as the scripts perform read-only static analysis.\n
  • Ingestion points: The tf_module_analyzer.py and tf_security_scanner.py scripts read .tf files from user-specified paths.\n
  • Boundary markers: No explicit boundary markers are used when reading files.\n
  • Capability inventory: The scripts perform read-only static analysis and output reports to the terminal.\n
  • Sanitization: No sanitization is performed on the input file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:18 AM
Security Audit — agent-trust-hub — terraform-patterns