terraform

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's testing workflow (references/testing-frameworks.md) explicitly instructs the agent to "Always use Terraform MCP to validate resource schemas" and shows mcp__terraform__search_providers / mcp__terraform__get_provider_details calls to load public provider documentation, meaning the agent will fetch and interpret external provider docs which can materially influence test generation and command choices.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 10:06 PM