terraform-state
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions and examples for executing the
terraformCLI, including subcommands likestate,import, andworkspace. These are standard administrative actions for managing infrastructure code. - [DATA_EXFILTRATION]: The skill documents how to access
terraform.tfstatefiles, which contain sensitive infrastructure mappings and metadata. It facilitates the transfer of this data using theterraform state pullandpushcommands. These operations target well-known and legitimate cloud services (AWS S3, Azure Blob Storage, and Terraform Cloud) which are considered safe destinations for their intended purpose. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing resource metadata and identifiers (e.g., AWS instance IDs, organization names) retrieved from external providers. While this represents a surface where malicious strings could be injected into the agent's context via resource names, the skill uses standard CLI tool boundaries and does not contain unsafe interpolation patterns.
- [SAFE]: All resource references, such as AWS S3 backends and Azure Storage accounts, use standard documentation placeholders. The skill promotes security best practices, including the use of state locking to prevent concurrent modifications and KMS encryption to protect sensitive data at rest.
Audit Metadata