terraform-state

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing the terraform CLI, including subcommands like state, import, and workspace. These are standard administrative actions for managing infrastructure code.
  • [DATA_EXFILTRATION]: The skill documents how to access terraform.tfstate files, which contain sensitive infrastructure mappings and metadata. It facilitates the transfer of this data using the terraform state pull and push commands. These operations target well-known and legitimate cloud services (AWS S3, Azure Blob Storage, and Terraform Cloud) which are considered safe destinations for their intended purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing resource metadata and identifiers (e.g., AWS instance IDs, organization names) retrieved from external providers. While this represents a surface where malicious strings could be injected into the agent's context via resource names, the skill uses standard CLI tool boundaries and does not contain unsafe interpolation patterns.
  • [SAFE]: All resource references, such as AWS S3 backends and Azure Storage accounts, use standard documentation placeholders. The skill promotes security best practices, including the use of state locking to prevent concurrent modifications and KMS encryption to protect sensitive data at rest.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:22 PM
Security Audit — agent-trust-hub — terraform-state