terraform-engineer
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow includes standard infrastructure management commands using the terraform CLI and tflint. These are legitimate tools for the skill's intended purpose and include explicit validation and error-handling steps.
- [EXTERNAL_DOWNLOADS]: The documentation suggests the use of standard industry tools like tflint, pre-commit, and terratest, as well as official GitHub Actions from trusted providers such as Hashicorp and Bridgecrew. These references target well-known, established services.
- [DATA_EXFILTRATION]: Documentation regarding the ~/.aws/credentials path is provided solely as a configuration example for provider authentication. There is no evidence of instructions that would exfiltrate or unsafely process sensitive local data.
- [PROMPT_INJECTION]: The skill processes user-defined infrastructure requirements. Although this presents a surface for indirect prompt injection, the skill includes strong mitigations such as mandatory security constraints, the use of sensitive variable markers, and encryption best practices.
Audit Metadata