iac-data-engineering-terraform
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
terraform apply -auto-approve. This flag suppresses the interactive prompt that allows a user to review planned infrastructure changes before execution, which is a high-risk practice for autonomous agents as it removes human oversight. - [DATA_EXFILTRATION]: The instruction to use
cat terraform/terraform.tfstateprints the full contents of the Terraform state file to the session output. Terraform state files frequently contain sensitive information in plain text, such as database passwords, initial credentials, and metadata that could be used for further exploitation. - [DATA_EXFILTRATION]: The Terraform configuration accesses
~/.ssh/id_rsa.pubto set up an AWS key pair. Accessing the.sshdirectory is a sensitive file operation, and while the public key is not secret, it establishes a pattern of accessing restricted user directories. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection by processing external configuration files without validation.
- Ingestion points: Input variables in
variables.tf, values interraform.tfvars, the public key at~/.ssh/id_rsa.pub, and theterraform.tfstatefile. - Boundary markers: No boundary markers or delimiters are used to wrap data ingested from these files to prevent instructions from being interpreted as commands.
- Capability inventory: The skill has the capability to create and modify AWS resources (
terraform apply), manage IAM roles/policies, and execute shell scripts on EC2 instances (user_data). - Sanitization: The skill lacks sanitization logic for data interpolated into Terraform configurations or EC2 initialization scripts.
Audit Metadata