terraform-data-engineering-iac

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download the Terraform binary from releases.hashicorp.com and the AWS CLI from awscli.amazonaws.com. These are official, well-known distribution domains for these tools.
  • [COMMAND_EXECUTION]: The documentation provides numerous shell commands for tool installation (wget, curl, unzip), AWS configuration (aws configure), and Terraform lifecycle management (terraform init, plan, apply, destroy). These commands are consistent with the skill's purpose of managing infrastructure.
  • [PRIVILEGE_ESCALATION]: The skill uses sudo for installing binaries to system paths (e.g., /usr/local/bin/) and for executing the AWS CLI installer. It also uses sudo within an EC2 user_data script for system updates and package installation. These are standard administrative requirements for software installation.
  • [DATA_EXPOSURE]: The troubleshooting section mentions exporting AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables. These are handled safely using variable placeholders ("${AWS_ACCESS_KEY_ID}") rather than exposing actual credentials.
  • [REMOTE_CODE_EXECUTION]: The EC2 resource definition includes a user_data script that automatically installs Python libraries (pandas, boto3, apache-airflow) from official package registries upon instance launch.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — terraform-data-engineering-iac