terraform-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful infrastructure and development tools, including
terraform,tflint,go test,opa, andpre-commit. These tools have broad access to the local filesystem and remote cloud environments. - [DATA_EXPOSURE]: Documentation within the skill (
references/providers.md) references sensitive local file paths such as~/.aws/credentials. While these are used as standard examples for Terraform authentication, they highlight the agent's potential interaction with highly sensitive credential stores. - [INDIRECT_PROMPT_INJECTION]: The core workflow involves analyzing untrusted inputs like "existing code" and "infrastructure requirements." While the skill incorporates a human-in-the-loop approval step for infrastructure changes, it lacks explicit sanitization or boundary markers (delimiters) for processing potentially adversarial HCL code or requirements.
- [METADATA_POISONING]: The
SKILL.mdmetadata identifies the author ashttps://github.com/Jeffallan, which contradicts the provided submission context ofsodiqabdulwaris. Deceptive or inconsistent metadata can be a sign of reused or unauthorized content. - [EXTERNAL_DOWNLOADS]: The skill relies on
terraform initandgo mod downloadto fetch providers, modules, and dependencies from external public registries. Furthermore, the skill references a documentation URL (jeffallan.github.io) that has been blacklisted by automated reputation scanners.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata