ia-terraform
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions focus strictly on Terraform and Infrastructure-as-Code best practices. No attempts to bypass system prompts or influence the AI's core behavior were found.
- [CREDENTIALS_UNSAFE]: The skill includes explicit security guidelines to avoid hardcoding secrets and to use the
sensitive = trueattribute for variables. No hardcoded credentials were found in the skill source. - [EXTERNAL_DOWNLOADS]: No unauthorized or suspicious external downloads were identified. The skill references well-known industry security tools such as
tflint,trivy, andcheckovas part of a recommended testing workflow. - [DATA_EXFILTRATION]: The skill does not contain instructions to transmit data to external servers or access sensitive local files like SSH keys or environment configurations.
- [COMMAND_EXECUTION]: The skill recommends standard Terraform and OpenTofu CLI commands for formatting, validation, and security scanning. These commands are typical for the described domain and are intended for use in a developer environment.
Audit Metadata