terraform-policy

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [Trusted Vendor Integration]: The skill references sub-skill components and documentation hosted by HashiCorp, a verified and trusted organization. \n
  • Evidence: SKILL.md provides installation instructions using the npx utility that target official HashiCorp repositories. \n
  • Context: Utilizing resources from established tech companies is a secure and standard practice for ensuring skill reliability.\n\n- [Security-Focused Design Patterns]: The instructions include mandatory patterns for checking critical cloud configurations, specifically targeting IAM privilege auditing and S3 resource relationships. \n
  • Evidence: references/tfpolicy-author.md mandates the use of specific resource policy blocks for all IAM inline policy types to prevent bypasses. \n
  • Context: These guidelines ensure that the generated policies are comprehensive and minimize potential security gaps in managed infrastructure.\n\n- [Syntax and Runtime Guardrails]: The skill features a 'Verified Syntax' guide designed to help the agent produce high-quality HCL code that is resilient to runtime errors and syntax pitfalls. \n
  • Evidence: references/verified-syntax.md contains validated patterns for null safety, semantic versioning, and collection handling. \n
  • Context: By strictly defining correct syntax and common mistakes, the skill reduces the likelihood of accidental vulnerabilities or logic errors in the policy code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 12:01 AM
Security Audit — agent-trust-hub — terraform-policy