terraform-policy
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [Trusted Vendor Integration]: The skill references sub-skill components and documentation hosted by HashiCorp, a verified and trusted organization. \n
- Evidence:
SKILL.mdprovides installation instructions using thenpxutility that target official HashiCorp repositories. \n - Context: Utilizing resources from established tech companies is a secure and standard practice for ensuring skill reliability.\n\n- [Security-Focused Design Patterns]: The instructions include mandatory patterns for checking critical cloud configurations, specifically targeting IAM privilege auditing and S3 resource relationships. \n
- Evidence:
references/tfpolicy-author.mdmandates the use of specific resource policy blocks for all IAM inline policy types to prevent bypasses. \n - Context: These guidelines ensure that the generated policies are comprehensive and minimize potential security gaps in managed infrastructure.\n\n- [Syntax and Runtime Guardrails]: The skill features a 'Verified Syntax' guide designed to help the agent produce high-quality HCL code that is resilient to runtime errors and syntax pitfalls. \n
- Evidence:
references/verified-syntax.mdcontains validated patterns for null safety, semantic versioning, and collection handling. \n - Context: By strictly defining correct syntax and common mistakes, the skill reduces the likelihood of accidental vulnerabilities or logic errors in the policy code.
Audit Metadata