terraform-iac
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted Terraform HCL code, which presents an attack surface for indirect prompt injection if the code contains malicious instructions or configurations.
- Ingestion points: User-provided infrastructure-as-code files and project structures evaluated by the agent.
- Boundary markers: Instructions do not define specific delimiters or provide "ignore embedded instructions" directives for the HCL content being processed.
- Capability inventory: The skill leverages the
terraformCLI, which can execute arbitrary shell commands vialocal-execprovisioners orexternaldata sources. - Sanitization: No explicit sanitization or validation of the input HCL content is described.
- [COMMAND_EXECUTION]: The skill instructs the agent to automatically execute a shell command (
ls) upon activation to check for the presence of recommended companion skills in the user's environment. - [DATA_EXFILTRATION]: The activation routine performs reconnaissance on the user's filesystem by checking for the existence of directories in the home folder (e.g.,
~/.claude/skills/), which exposes metadata about the user's local configuration.
Audit Metadata