Terraform-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and manage Terraform configuration and state files. Processing these external inputs represents a theoretical ingestion surface for indirect prompt injection if the files contain malicious instructions.
  • Ingestion points: Terraform configuration files (.tf), variable definition files, and infrastructure state files.
  • Boundary markers: The skill includes high-level procedural instructions for manual verification but lacks technical delimiters to isolate processed data from the agent's instructions.
  • Capability inventory: The skill utilizes the terraform CLI tool, which is capable of file system modifications and network operations for provider and module management.
  • Sanitization: No explicit technical sanitization or validation logic for the HashiCorp Configuration Language (HCL) content is defined.
  • [EXTERNAL_DOWNLOADS]: The skill and its accompanying safety documentation reference the author's official GitHub repository and website for reporting security issues and accessing further documentation. These are documented as legitimate vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:31 PM
Security Audit — agent-trust-hub — Terraform-hardened