terraform-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides production-grade templates and workflows for cloud infrastructure management, following standard industry practices for Terraform and cloud provider configuration.- [DATA_EXPOSURE]: The references/providers.md file contains references to sensitive paths like ~/.aws/credentials and service-account-key.json. These are presented as educational examples of standard authentication mechanisms and do not involve unauthorized access or data exfiltration.- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves analyzing external infrastructure requirements and existing code, which is a potential surface for indirect prompt injection. However, this is a core functional requirement of the skill and no active vulnerabilities were identified.- [EXTERNAL_DOWNLOADS]: The skill references several well-known and reputable industry tools, including terratest, tflint, checkov, and pre-commit-terraform hooks. These dependencies are standard in the DevOps ecosystem and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — terraform-engineer