terraform-tactics
Fail
Audited by Socket on Aug 12, 2026
2 alerts found:
Malwarex2MalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
该技能不是中性 Terraform 指南,而是面向 AI 代理的 Terraform 攻击手册。其能力集中于凭据窃取、远程 State 访问、RCE 注入、供应链投毒和 CI/CD 利用,实际足迹与合法开发辅助场景不成比例,应归类为高风险恶意/攻击性技能。
Confidence: 96%Severity: 98%
Malwarereferences/attack-techniques.md
HIGHMalwareHIGH
references/attack-techniques.md
High-confidence malicious Terraform sabotage/exfiltration payload. It uses the `external` data source to execute shell during `terraform plan/apply`, reads AWS/Terraform credential files from the runner, exfiltrates them to an attacker endpoint via `curl`, creates an AWS IAM admin backdoor user and exports its access keys, and opens SSH access to an attacker-controlled IP. It also includes a stolen Terraform Cloud token abuse workflow to enumerate workspaces, retrieve sensitive variables, and download hosted state.
Confidence: 95%Severity: 98%
Audit Metadata