terraform-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful infrastructure and development tools, including terraform, tflint, go test, opa, and pre-commit. These tools have broad access to the local filesystem and remote cloud environments.
  • [DATA_EXPOSURE]: Documentation within the skill (references/providers.md) references sensitive local file paths such as ~/.aws/credentials. While these are used as standard examples for Terraform authentication, they highlight the agent's potential interaction with highly sensitive credential stores.
  • [INDIRECT_PROMPT_INJECTION]: The core workflow involves analyzing untrusted inputs like "existing code" and "infrastructure requirements." While the skill incorporates a human-in-the-loop approval step for infrastructure changes, it lacks explicit sanitization or boundary markers (delimiters) for processing potentially adversarial HCL code or requirements.
  • [METADATA_POISONING]: The SKILL.md metadata identifies the author as https://github.com/Jeffallan, which contradicts the provided submission context of sodiqabdulwaris. Deceptive or inconsistent metadata can be a sign of reused or unauthorized content.
  • [EXTERNAL_DOWNLOADS]: The skill relies on terraform init and go mod download to fetch providers, modules, and dependencies from external public registries. Furthermore, the skill references a documentation URL (jeffallan.github.io) that has been blacklisted by automated reputation scanners.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — terraform-engineer