terraform-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill's core workflow instructs the agent to execute
terraform planandterraform apply. These commands represent high-privilege actions that can create, modify, or destroy cloud infrastructure resources. These operations should only be performed with appropriate IAM permissions and human-in-the-loop review of the plan output. - [CREDENTIALS_UNSAFE]: Reference documentation within the skill mentions standard but sensitive file paths for provider authentication, specifically
~/.aws/credentialsfor AWS and service account key files for Google Cloud. While these are legitimate configuration methods for Terraform, they point to locations where sensitive credentials reside. - [DYNAMIC_EXECUTION]: The agent is designed to generate Infrastructure-as-Code (HCL) based on requirements and then execute that code through the Terraform CLI. This runtime execution of agent-generated content is a fundamental part of the skill's purpose but carries risks if the generated code contains unintended or malicious resource definitions.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes external Terraform files (
.tf,.tfvars) during its core workflow. This creates a surface for indirect prompt injection, where malicious instructions embedded in infrastructure code or variables could attempt to influence the agent's behavior during the planning or implementation phase. - [EXTERNAL_DOWNLOADS]: The skill provides guidance for installing and using well-known third-party tools such as TFLint, Checkov, and Terratest from public repositories. These are standard industry utilities for infrastructure linting, security scanning, and testing.
Audit Metadata