terraform-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow includes standard infrastructure management commands using the terraform CLI and tflint. These are legitimate tools for the skill's intended purpose and include explicit validation and error-handling steps.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests the use of standard industry tools like tflint, pre-commit, and terratest, as well as official GitHub Actions from trusted providers such as Hashicorp and Bridgecrew. These references target well-known, established services.
  • [DATA_EXFILTRATION]: Documentation regarding the ~/.aws/credentials path is provided solely as a configuration example for provider authentication. There is no evidence of instructions that would exfiltrate or unsafely process sensitive local data.
  • [PROMPT_INJECTION]: The skill processes user-defined infrastructure requirements. Although this presents a surface for indirect prompt injection, the skill includes strong mitigations such as mandatory security constraints, the use of sensitive variable markers, and encryption best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 09:32 AM
Security Audit — agent-trust-hub — terraform-engineer