infrastructure-as-code

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security violations were detected in the skill instructions or code examples. The external dependencies used in the examples, such as official Terraform providers and Pulumi packages, are from well-known and established sources.- [PROMPT_INJECTION]: The skill was evaluated for indirect prompt injection risks as it generates infrastructure code based on user-provided requirements.
  • Ingestion points: User-specified configuration values (e.g., VPC CIDRs, resource names) interpolated into the IaC templates in SKILL.md.
  • Boundary markers: Absent; the templates do not use explicit delimiters to separate user data from resource configuration syntax.
  • Capability inventory: Enables the generation of resource definitions for networking, compute (EKS/ECS), and database services.
  • Sanitization: Absent in the static templates; security relies on the agent's output generation and the validation logic of the infrastructure tools themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 12:48 PM
Security Audit — agent-trust-hub — infrastructure-as-code