infrastructure-as-code

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a documentation and validation assistant for Infrastructure as Code (IaC) best practices. All analyzed files contain legitimate educational content, patterns, and validation logic for tools like Terraform and Pulumi without any signs of malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing user-provided code and configurations (Ingestion points). It mitigates potential injection by instructing the agent to strictly follow local reference files as the primary source of truth (Boundary markers). The agent's capabilities are limited to generating advice and code snippets based on provided documentation (Capability inventory). No explicit sanitization of user code is defined, but the agent's restricted scope limits potential impact (Sanitization).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:55 PM
Security Audit — agent-trust-hub — infrastructure-as-code