terraform
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides extensive defensive guidelines and mandatory security rules for the AI agent. It explicitly prohibits hardcoded credentials, overly permissive IAM policies, and public network exposure in infrastructure definitions.
- [SAFE]: Documentation includes detailed guidance on PCI-DSS 4.0 requirements, state file encryption (S3 native and OpenTofu client-side), and audit trail architecture.
- [SAFE]: No obfuscation, data exfiltration, or unauthorized remote execution patterns were detected. All external references are to well-known infrastructure tools (Terraform, TFLint, Checkov) or trusted organizations.
- [SAFE]: The skill demonstrates high security maturity by providing warnings about historical supply chain attacks (e.g., tj-actions, Trivy) and recommending pinning dependencies to commit SHAs.
Audit Metadata