terraform-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides production-grade templates and workflows for cloud infrastructure management, following standard industry practices for Terraform and cloud provider configuration.- [DATA_EXPOSURE]: The
references/providers.mdfile contains references to sensitive paths like~/.aws/credentialsandservice-account-key.json. These are presented as educational examples of standard authentication mechanisms and do not involve unauthorized access or data exfiltration.- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves analyzing external infrastructure requirements and existing code, which is a potential surface for indirect prompt injection. However, this is a core functional requirement of the skill and no active vulnerabilities were identified.- [EXTERNAL_DOWNLOADS]: The skill references several well-known and reputable industry tools, includingterratest,tflint,checkov, andpre-commit-terraformhooks. These dependencies are standard in the DevOps ecosystem and are documented neutrally.
Audit Metadata