infrastructure-cicd-data-engineering
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The drift detection workflow in
.github/workflows/drift-detection.ymlpresents an indirect injection surface by reading raw Terraform plan output and posting it to a GitHub issue. - Ingestion points:
plan.txt(output fromterraform show -no-color). - Boundary markers: None; the content is wrapped in markdown code blocks but not sanitized for instruction markers.
- Capability inventory: The skill has permissions to create GitHub issues, comment on pull requests, and execute arbitrary Terraform commands (
plan,apply,destroy) via the OIDC-linked IAM role. - Sanitization: None; the script reads the file content and interpolates it directly into the
bodyfield of the GitHub API call. - [PRIVILEGE_ESCALATION]: The bootstrap Terraform configuration (
terraform/bootstrap/main.tf) attaches theAdministratorAccessmanaged policy to the IAM role intended for GitHub Actions. - While common for infrastructure management, this granting of maximum privileges via the
aws_iam_role_policy_attachmentresource increases the impact of a potential GitHub Actions environment or repository compromise.
Audit Metadata