refactor-module
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Terraform configuration files from the user-provided
source_directoryto perform analysis and refactoring. - Ingestion points: Files within the user-specified
source_directory(SKILL.md). - Boundary markers: None; the agent is instructed to analyze and transform the provided code directly without explicit delimiters or warnings for embedded instructions.
- Capability inventory: The skill performs file read/write operations, generates HCL code, and executes
terraform stateCLI commands (SKILL.md). - Sanitization: None; the skill relies on the agent's parsing logic without explicit sanitization or validation of the input configuration.
- [EXTERNAL_DOWNLOADS]: Fetches additional skill definitions and style guidelines from HashiCorp's official GitHub repository.
- Evidence: Links to
raw.githubusercontent.com/hashicorp/agent-skills/...in the "Related Skills" section of SKILL.md. - [COMMAND_EXECUTION]: Instructs the agent to execute
terraform state mvcommands to facilitate state migration during the refactoring process. - Evidence: Shell command patterns provided in the "Manual State Migration (Pre-1.1)" section of SKILL.md.
Audit Metadata