terraform-security-audit
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a security auditing framework for Terraform codebases, focusing on infrastructure best practices like Least Privilege, Network Isolation, and Data Encryption.
- [SAFE]: The
allowed_toolsare restricted toRead,Glob, andGrep, which are passive, read-only operations used for scanning local files without risk of system modification or data exfiltration. - [SAFE]: No malicious patterns such as prompt injection, obfuscation, or remote code execution were detected. The examples of 'insecure' code are clearly labeled for instructional purposes and are not executable instructions.
- [SAFE]: The skill promotes secure secrets management by instructing the agent to check for sensitive variables and the presence of secret-scanning hooks.
Audit Metadata