terraform-data-engineering-iac
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download the Terraform binary from
releases.hashicorp.comand the AWS CLI fromawscli.amazonaws.com. These are official, well-known distribution domains for these tools. - [COMMAND_EXECUTION]: The documentation provides numerous shell commands for tool installation (
wget,curl,unzip), AWS configuration (aws configure), and Terraform lifecycle management (terraform init,plan,apply,destroy). These commands are consistent with the skill's purpose of managing infrastructure. - [PRIVILEGE_ESCALATION]: The skill uses
sudofor installing binaries to system paths (e.g.,/usr/local/bin/) and for executing the AWS CLI installer. It also usessudowithin an EC2user_datascript for system updates and package installation. These are standard administrative requirements for software installation. - [DATA_EXPOSURE]: The troubleshooting section mentions exporting
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEYenvironment variables. These are handled safely using variable placeholders ("${AWS_ACCESS_KEY_ID}") rather than exposing actual credentials. - [REMOTE_CODE_EXECUTION]: The EC2 resource definition includes a
user_datascript that automatically installs Python libraries (pandas,boto3,apache-airflow) from official package registries upon instance launch.
Audit Metadata