Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions skills/hashicorp-aws-ami-builder/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/packer/skills/aws-ami-builder"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-azure-image-builder/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/packer/skills/azure-image-builder"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-azure-verified-modules/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/azure-verified-modules"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-new-terraform-provider/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/new-terraform-provider"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-actions/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-actions"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-configuration/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,9 +15,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-configuration"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-docs/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-docs"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-ephemeral-resources/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-ephemeral-resources"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-framework-migration/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-framework-migration"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-resources/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-resources"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-provider-test-patterns/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/provider-test-patterns"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
6 changes: 4 additions & 2 deletions skills/hashicorp-push-to-registry/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/packer/skills/push-to-registry"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand All @@ -27,3 +27,5 @@ security:
reason: "FP: matched Terraform HCL string-interpolation syntax (`${...}`) or GitHub Actions `secrets.*` references in documented configuration/CI examples (e.g. SKILL.md:38, SKILL.md:130) β€” standard HCL/CI syntax, not injected secrets."
- rule_id: ATR_2026_00114
reason: "FP: matched placeholder credential values like `CLIENT_SECRET=\"your-client-secret\"` in documented example commands (e.g. SKILL.md:73) β€” literal placeholders, not real secrets."
- rule_id: LLM_SUPPLY_CHAIN_ATTACK
reason: "Accepted risk: documented `hashicorp/setup-packer@main` CI example (SKILL.md:125); operator accepts the mutable ref based on trust in the HashiCorp publisher."
4 changes: 2 additions & 2 deletions skills/hashicorp-refactor-module/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/refactor-module"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-run-acceptance-tests/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/run-acceptance-tests"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-terraform-policy/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/terraform-policy"
version: "0.2.0"
version: "0.3.0"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-terraform-search-import/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/terraform-search-import"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-terraform-stacks/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/terraform-stacks"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-terraform-style-guide/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/terraform-style-guide"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
4 changes: 2 additions & 2 deletions skills/hashicorp-terraform-test/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/terraform/skills/terraform-test"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand Down
10 changes: 7 additions & 3 deletions skills/hashicorp-windows-builder/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ metadata:

spec:
repository: "https://github.com/hashicorp/agent-skills"
ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10
ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10
path: "plugins/packer/skills/windows-builder"
version: "0.2.0"
version: "0.2.1"

provenance:
repository_uri: "https://github.com/hashicorp/agent-skills"
Expand All @@ -22,7 +22,7 @@ security:
- rule_id: MANIFEST_MISSING_LICENSE
reason: "hashicorp/agent-skills is licensed MPL-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter."
- rule_id: ATR_2026_00010
reason: "FP: matched the documented Chocolatey bootstrap command `iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))` (SKILL.md:101) β€” the official Chocolatey install script run inside a Packer PowerShell provisioner to build a Windows image, not a hidden payload."
reason: "Risk accepted by maintainer (danbarr, 2026-09-18): matched the documented Chocolatey bootstrap command `iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))` (SKILL.md:108). This is Chocolatey's official HTTPS bootstrap script run inside a Packer PowerShell provisioner to build a Windows image; the mutable remote-script execution risk is explicit and accepted."
- rule_id: ATR_2026_00063
reason: "FP: matched words like \"exfil\"/\"upload\"/\"encrypt\" in documentation prose β€” either warning against exfiltration (design-principles guidance) or describing legitimate upload/encryption features (HCP Packer registry push, state upload, disk encryption) (e.g. SKILL.md:47), not exfiltration code."
- rule_id: ATR_2026_00064
Expand All @@ -31,3 +31,7 @@ security:
reason: "FP: matched Terraform HCL string-interpolation syntax (`${...}`) or GitHub Actions `secrets.*` references in documented configuration/CI examples (e.g. SKILL.md:28, SKILL.md:70) β€” standard HCL/CI syntax, not injected secrets."
- rule_id: ATR_2026_00091
reason: "FP: matched \"constructor\"/\"Constructor\" in Go code documentation describing struct initialization (e.g. SKILL.md:147), not an obfuscation pattern."
- rule_id: LLM_HARMFUL_CONTENT
reason: "Accepted risk: documented insecure/Basic WinRM bootstrap (SKILL.md:42-57) is required for Packer Windows builders; operator accepts it for temporary build targets with restricted network exposure."
- rule_id: LLM_SUPPLY_CHAIN_ATTACK
reason: "Risk accepted by maintainer (danbarr, 2026-09-18): the example uses Chocolatey's official HTTPS bootstrap script inside a Packer-built Windows image without pinning the script content or verifying a checksum. The supply-chain risk of executing that mutable vendor installer is explicit and accepted for this documented bootstrap workflow."
Loading