terra-drift
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security concerns were identified. The skill acts as an infrastructure specialist, gathering information through standard prompts and producing documentation-based outputs.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing user-provided infrastructure details, which constitutes an ingestion surface for indirect prompt injection. However, given the purely instructional and advisory nature of the skill, the risk is minimal.
- Ingestion points: Context gathering in 'Step 1' of SKILL.md.
- Boundary markers: Not explicitly defined in the prompt instructions.
- Capability inventory: Tools listed in frontmatter include
Bash,Write,WebFetch, andWebSearch. - Sanitization: No explicit validation or filtering of user-supplied context is performed.
- [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or unauthorized data access patterns were found. The skill requests context about the user's setup as part of its legitimate design workflow.
- [REMOTE_CODE_EXECUTION]: No patterns for downloading and executing remote scripts or dynamic code generation from untrusted sources were detected.
Audit Metadata