terraform-azurerm-set-diff-analyzer
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- NO_CODE (SAFE): The script
scripts/analyze_plan.pyreferenced inSKILL.mdandscripts/README.mdis not included in the skill files. Only documentation and a JSON configuration file are provided.\n- Indirect Prompt Injection (SAFE): The skill is designed to process untrusted Terraform plan output, creating a potential attack surface. Evidence Chain: 1. Ingestion points: Processes externalplan.jsonoutput via command-line arguments. 2. Boundary markers: None identified in the provided documentation. 3. Capability inventory: Execution logic is missing; documentation suggests local data processing for reporting. 4. Sanitization: Cannot be evaluated as the source code is not provided.
Audit Metadata