terraform-tactics

Fail

Audited by Socket on Aug 12, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

该技能不是中性 Terraform 指南,而是面向 AI 代理的 Terraform 攻击手册。其能力集中于凭据窃取、远程 State 访问、RCE 注入、供应链投毒和 CI/CD 利用,实际足迹与合法开发辅助场景不成比例,应归类为高风险恶意/攻击性技能。

Confidence: 96%Severity: 98%
MalwareHIGH
references/attack-techniques.md

High-confidence malicious Terraform sabotage/exfiltration payload. It uses the `external` data source to execute shell during `terraform plan/apply`, reads AWS/Terraform credential files from the runner, exfiltrates them to an attacker endpoint via `curl`, creates an AWS IAM admin backdoor user and exports its access keys, and opens SSH access to an attacker-controlled IP. It also includes a stolen Terraform Cloud token abuse workflow to enumerate workspaces, retrieve sensitive variables, and download hosted state.

Confidence: 95%Severity: 98%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fterraform-tactics%2F@da1976c46371cd8524569d7fcb667df3aa0fe3f1089c9e8e6785d1cc71a2cb9e
Security Audit — socket — terraform-tactics