skills/mukul975/anthropic-cybersecurity-skills/auditing-terraform-infrastructure-for-security/Gen Agent Trust Hub
auditing-terraform-infrastructure-for-security
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/agent.pyscript executes external security scanning binaries as its primary function. - Evidence: The script uses
subprocess.runto callcheckovandtfsecbinaries with user-provided directory paths. - Context: The execution utilizes safe argument list formatting to prevent shell injection and is strictly limited to the intended purpose of scanning infrastructure code.
- [EXTERNAL_DOWNLOADS]: The skill identifies several well-known security tools as necessary prerequisites.
- Evidence:
SKILL.mdlistscheckov,tfsec,terrascan, andOpen Policy Agent (OPA)as required tools. - Context: These tools are established open-source security projects from well-known organizations. References to these resources are informative and necessary for the skill's operation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration data which creates a potential surface for indirect injection, though this is expected for an auditing tool.
- Ingestion points:
scripts/agent.pyreads and parses Terraform plan JSON files (e.g.,plan_json_path). - Boundary markers: None are explicitly implemented in the agent's report generation logic.
- Capability inventory: The skill has permissions to execute system commands (
subprocess.run) and perform file operations. - Sanitization: No specific sanitization of the input JSON content is performed prior to parsing and reporting.
- [SAFE]: No signs of obfuscation, hardcoded credentials, or unauthorized data exfiltration were found. The skill operates locally on user-provided files and generates local output reports.
Audit Metadata