terraform-iac-data-engineering
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the Terraform CLI from HashiCorp's official release site and the AWS CLI from Amazon Web Services' official download domain.
- [EXTERNAL_DOWNLOADS]: Instructs the cloning of an external repository from GitHub:
https://github.com/josephmachado/iac-for-data-engineering-terraform-.git. - [COMMAND_EXECUTION]: Includes instructions for the execution of various shell commands, including
terraform init,terraform apply, andaws configureto manage cloud credentials and infrastructure. - [COMMAND_EXECUTION]: Recommends the use of
terraform apply -auto-approve, which executes infrastructure changes without the standard interactive user confirmation. - [PRIVILEGE_ESCALATION]: Contains instructions to use
sudofor moving binary files to/usr/local/bin/and for running system-level installation scripts for the AWS CLI. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill guides the agent to clone and process content from a remote GitHub repository (
SKILL.md). - Boundary markers: There are no boundary markers or instructions to treat the external repository content as untrusted.
- Capability inventory: The skill possesses capabilities for shell execution, local file system manipulation, and remote AWS resource provisioning (S3, EC2, IAM).
- Sanitization: There is no evidence of sanitization or validation of the content retrieved from the external repository.
Audit Metadata