terraform-plan-review
Fail
Audited by Snyk on Mar 11, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill instructs the agent to read plan/.tf/.tfvars files and include attribute values and diffs verbatim in the generated report (e.g., key_attribute = "value", attribute: "old" → "new"), which could expose API keys/passwords or other secrets present in those files.
Audit Metadata