iac-terraform
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security defaults for Infrastructure as Code (IaC) development on GCP.
- [SAFE]: It promotes the principle of least privilege by explicitly forbidding high-privilege IAM roles (roles/owner, roles/editor) and mandating additive IAM members over authoritative bindings.
- [SAFE]: The skill requires the use of remote GCS backends to prevent local state exposure and mandates 'prevent_destroy' flags on stateful resources to prevent accidental data loss.
- [SAFE]: No hardcoded credentials, malicious network operations, remote code execution, or obfuscated content were detected in the instructions or examples.
Audit Metadata