infrastructure-terraform
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard Terraform commands such as
init,plan,apply, anddestroyvia theBashtool to manage infrastructure lifecycles. - [EXTERNAL_DOWNLOADS]: Uses the HashiCorp Terraform Registry to download official providers and modules from trusted organizations for infrastructure provisioning.
- [PROMPT_INJECTION]: The skill processes HCL configuration files and command outputs, representing an indirect prompt injection surface. (1) Ingestion points: Uses the
Readtool to ingest local.tf,.tfvars, and.tfstatefiles. (2) Boundary markers: Relies on HCL syntax; no explicit natural language markers. (3) Capability inventory: PossessesBash,Write,Edit, andReadtools. (4) Sanitization: Relies on Terraform CLI's internal validation.
Audit Metadata