developing-terraform

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly educational and provides high-quality guidance for infrastructure-as-code (IaC) development using Terraform and Terragrunt.
  • [CREDENTIALS_UNSAFE]: Deterministic detectors identified potential hardcoded credentials in references/AWS-PRACTICE.md. Manual review confirms these are dummy placeholders (e.g., 'AKIAXXXXXXXXXXXXXXXX') used strictly for documenting configuration patterns. No actual secrets are exposed.
  • [EXTERNAL_DOWNLOADS]: The documentation includes instructions to download well-known technology tools like TFlint, Terragrunt, and AWS Nuke from official GitHub repositories. These are recognized services, and the instructions are standard for setting up a development environment.
  • [COMMAND_EXECUTION]: The skill documents the use of Terraform provisioners (local-exec, remote-exec) and CLI tools for infrastructure automation. These commands are typical for the stated purpose of the skill and include best practice advice such as using OIDC to avoid long-lived credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 11:13 PM