infrastructure-cicd-data-engineering

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The drift detection workflow in .github/workflows/drift-detection.yml presents an indirect injection surface by reading raw Terraform plan output and posting it to a GitHub issue.
  • Ingestion points: plan.txt (output from terraform show -no-color).
  • Boundary markers: None; the content is wrapped in markdown code blocks but not sanitized for instruction markers.
  • Capability inventory: The skill has permissions to create GitHub issues, comment on pull requests, and execute arbitrary Terraform commands (plan, apply, destroy) via the OIDC-linked IAM role.
  • Sanitization: None; the script reads the file content and interpolates it directly into the body field of the GitHub API call.
  • [PRIVILEGE_ESCALATION]: The bootstrap Terraform configuration (terraform/bootstrap/main.tf) attaches the AdministratorAccess managed policy to the IAM role intended for GitHub Actions.
  • While common for infrastructure management, this granting of maximum privileges via the aws_iam_role_policy_attachment resource increases the impact of a potential GitHub Actions environment or repository compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — infrastructure-cicd-data-engineering