infrastructure-terraform

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard Terraform commands such as init, plan, apply, and destroy via the Bash tool to manage infrastructure lifecycles.
  • [EXTERNAL_DOWNLOADS]: Uses the HashiCorp Terraform Registry to download official providers and modules from trusted organizations for infrastructure provisioning.
  • [PROMPT_INJECTION]: The skill processes HCL configuration files and command outputs, representing an indirect prompt injection surface. (1) Ingestion points: Uses the Read tool to ingest local .tf, .tfvars, and .tfstate files. (2) Boundary markers: Relies on HCL syntax; no explicit natural language markers. (3) Capability inventory: Possesses Bash, Write, Edit, and Read tools. (4) Sanitization: Relies on Terraform CLI's internal validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 07:09 PM