terraform
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation and Terraform (HCL) code examples designed to guide an AI agent in writing secure and maintainable infrastructure code.
- [SAFE]: Security-sensitive sections (e.g., [sec-no-hardcoded-secrets]) correctly identify insecure patterns like hardcoded credentials as 'Incorrect' and provide secure alternatives using AWS Secrets Manager and sensitive variables.
- [SAFE]: All example credentials found in the documentation (such as 'SuperSecret123' or 'AKIAIOSFODNN7EXAMPLE') are clearly labeled as dummy values for educational purposes.
- [SAFE]: No executable scripts, hidden commands, or external dependencies are included in the skill. The enforcement tools mentioned in the documentation (like 'terraform-checker.py') appear to be references to an external developer workflow and are not provided as part of the skill payload.
- [SAFE]: The skill promotes security best practices including IAM least privilege, encryption at rest, and VPC isolation.
Audit Metadata