terraform-iac-expert
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of documentation (SKILL.md) and standard metadata (plugin.json). It contains no executable scripts (Python, Node.js, Shell) or dynamic execution patterns.
- [SAFE]: Code examples provided are illustrative HCL (HashiCorp Configuration Language) for Terraform and YAML for GitHub Actions. These are standard infrastructure patterns and do not contain malicious instructions or exfiltration vectors.
- [SAFE]: The skill correctly demonstrates security best practices, such as using AWS Secrets Manager for sensitive data instead of hardcoding credentials, and marking sensitive outputs appropriately.
- [SAFE]: External references (e.g., hashicorp/setup-terraform, aws-actions/configure-aws-credentials) are to well-known, official GitHub Actions maintained by trusted providers.
Audit Metadata