infisical-terraform
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation and integration tool for the Infisical Terraform Provider. All HCL examples and configuration instructions follow security best practices for Infrastructure-as-Code (IaC).- [SAFE]: The skill promotes the use of ephemeral resources (introduced in Terraform 1.10) to ensure that sensitive secrets are fetched at runtime and never persisted in the Terraform state file, which is a significant security improvement over standard data sources.- [SAFE]: Authentication guidance focuses on secure Machine Identity patterns, specifically recommending OIDC for Terraform Cloud to eliminate the need for storing long-lived credentials in CI/CD environments.- [SAFE]: All referenced domains and provider sources belong to the vendor (Infisical) or well-known, trusted platforms (Terraform Cloud, CircleCI). No suspicious external downloads or remote code execution patterns were found.
Audit Metadata