import-infrastructure-as-code

Pass

Audited by Gen Agent Trust Hub on Mar 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard Azure CLI (az) and Terraform commands to identify resources and validate generated Infrastructure as Code. It includes specific constraints to treat Azure Resource IDs as cloud identifiers rather than local file system paths, mitigating potential file access vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: The skill retrieves module indexes and technical documentation from official Azure GitHub repositories and the Terraform Registry. These sources are recognized as trusted organizations and well-known services, and the data fetched is limited to documentation and configuration templates required for the skill's primary function.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill processes cloud resource metadata, it does not demonstrate any patterns of exfiltrating sensitive information to untrusted external domains. Data usage is confined to the local project environment and the authorized Azure context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 2, 2026, 08:37 AM