iac-terraform-data-engineering

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The instructions include a recommended IAM policy configuration that grants full access to S3, EC2, and IAM services (s3:*, ec2:*, iam:*). Providing such broad permissions increases the risk of account-wide compromise if the credentials are leaked or misused. Additionally, the skill demonstrates reading and parsing the terraform.tfstate file, which often contains sensitive resource metadata and identifiers.
  • [PRIVILEGE_ESCALATION]: The skill provides a Terraform configuration for a security group that allows inbound traffic on port 22 (SSH) from any IP address (0.0.0.0/0). This is a common misconfiguration that exposes cloud instances to brute-force and unauthorized access attempts from the public internet.
  • [COMMAND_EXECUTION]: The skill provides shell commands for high-impact operations, such as terraform apply -auto-approve and terraform destroy. These commands allow for the automated creation and destruction of entire infrastructure environments without manual confirmation, posing a risk of accidental resource loss or service disruption.
  • [DATA_EXFILTRATION]: The skill demonstrates how to read the contents of the terraform.tfstate file using cat and jq. Exposing the contents of a state file can leak sensitive information about the architecture and configuration of the data platform to unauthorized users or automated logs.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the AWS provider from HashiCorp's registry during terraform init and recommends downloading the Terraform and AWS CLIs from their official sources. These references target well-known services and are part of the standard toolchain setup.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — iac-terraform-data-engineering