refactor-module

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Terraform configuration files from the user-provided source_directory to perform analysis and refactoring.
  • Ingestion points: Files within the user-specified source_directory (SKILL.md).
  • Boundary markers: None; the agent is instructed to analyze and transform the provided code directly without explicit delimiters or warnings for embedded instructions.
  • Capability inventory: The skill performs file read/write operations, generates HCL code, and executes terraform state CLI commands (SKILL.md).
  • Sanitization: None; the skill relies on the agent's parsing logic without explicit sanitization or validation of the input configuration.
  • [EXTERNAL_DOWNLOADS]: Fetches additional skill definitions and style guidelines from HashiCorp's official GitHub repository.
  • Evidence: Links to raw.githubusercontent.com/hashicorp/agent-skills/... in the "Related Skills" section of SKILL.md.
  • [COMMAND_EXECUTION]: Instructs the agent to execute terraform state mv commands to facilitate state migration during the refactoring process.
  • Evidence: Shell command patterns provided in the "Manual State Migration (Pre-1.1)" section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — refactor-module