terraform-skill

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and provides well-structured guidance for infrastructure-as-code. It contains no malicious code or suspicious patterns.\n- [EXTERNAL_DOWNLOADS]: The skill references installation scripts for industry-standard tools like TFLint and Trivy from official GitHub repositories. These are well-known, trusted sources and the installation patterns follow established DevOps best practices.\n- [COMMAND_EXECUTION]: Contains extensive examples of command-line operations for Terraform, OpenTofu, and related security tools (Checkov, Trivy). These examples are within the expected scope for the skill and are provided for user implementation.\n- [REMOTE_CODE_EXECUTION]: Provides templates for tool installation that involve piping remote scripts to a shell. These are documented as standard setup procedures for official, well-known third-party tools and are considered safe within this context.\n- [DATA_EXFILTRATION]: No evidence of unauthorized data access or transmission. The skill emphasizes secure secrets management using platform-native tools like AWS Secrets Manager and provides guidance on securing state files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM