iac-terraform-data-engineering
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The instructions include a recommended IAM policy configuration that grants full access to S3, EC2, and IAM services (
s3:*,ec2:*,iam:*). Providing such broad permissions increases the risk of account-wide compromise if the credentials are leaked or misused. Additionally, the skill demonstrates reading and parsing theterraform.tfstatefile, which often contains sensitive resource metadata and identifiers. - [PRIVILEGE_ESCALATION]: The skill provides a Terraform configuration for a security group that allows inbound traffic on port 22 (SSH) from any IP address (
0.0.0.0/0). This is a common misconfiguration that exposes cloud instances to brute-force and unauthorized access attempts from the public internet. - [COMMAND_EXECUTION]: The skill provides shell commands for high-impact operations, such as
terraform apply -auto-approveandterraform destroy. These commands allow for the automated creation and destruction of entire infrastructure environments without manual confirmation, posing a risk of accidental resource loss or service disruption. - [DATA_EXFILTRATION]: The skill demonstrates how to read the contents of the
terraform.tfstatefile usingcatandjq. Exposing the contents of a state file can leak sensitive information about the architecture and configuration of the data platform to unauthorized users or automated logs. - [EXTERNAL_DOWNLOADS]: The skill fetches the AWS provider from HashiCorp's registry during
terraform initand recommends downloading the Terraform and AWS CLIs from their official sources. These references target well-known services and are part of the standard toolchain setup.
Audit Metadata