terraform-specialist

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a workflow that ingests external data from the context7 MCP, creating a surface for indirect prompt injection.\n
  • Ingestion points: The skill fetches Terraform provider documentation and library examples via the get-library-docs tool of the context7 MCP.\n
  • Boundary markers: The instructions do not define clear delimiters or specific instructions to ignore potentially malicious embedded content within the retrieved documentation.\n
  • Capability inventory: The agent is granted access to the Bash tool, enabling it to execute commands and scripts.\n
  • Sanitization: There are no explicit steps provided to sanitize or validate the external content before processing.\n- [COMMAND_EXECUTION]: The skill is configured to use the Bash tool to perform automation tasks, including the creation and execution of Makefiles, migration scripts, and pre-commit hooks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:23 AM
Security Audit — agent-trust-hub — terraform-specialist