iac-data-engineering-terraform

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use terraform apply -auto-approve. This flag suppresses the interactive prompt that allows a user to review planned infrastructure changes before execution, which is a high-risk practice for autonomous agents as it removes human oversight.
  • [DATA_EXFILTRATION]: The instruction to use cat terraform/terraform.tfstate prints the full contents of the Terraform state file to the session output. Terraform state files frequently contain sensitive information in plain text, such as database passwords, initial credentials, and metadata that could be used for further exploitation.
  • [DATA_EXFILTRATION]: The Terraform configuration accesses ~/.ssh/id_rsa.pub to set up an AWS key pair. Accessing the .ssh directory is a sensitive file operation, and while the public key is not secret, it establishes a pattern of accessing restricted user directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection by processing external configuration files without validation.
  • Ingestion points: Input variables in variables.tf, values in terraform.tfvars, the public key at ~/.ssh/id_rsa.pub, and the terraform.tfstate file.
  • Boundary markers: No boundary markers or delimiters are used to wrap data ingested from these files to prevent instructions from being interpreted as commands.
  • Capability inventory: The skill has the capability to create and modify AWS resources (terraform apply), manage IAM roles/policies, and execute shell scripts on EC2 instances (user_data).
  • Sanitization: The skill lacks sanitization logic for data interpolated into Terraform configurations or EC2 initialization scripts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — iac-data-engineering-terraform