diff --git a/skills/hashicorp-aws-ami-builder/spec.yaml b/skills/hashicorp-aws-ami-builder/spec.yaml index 145f4f34..c34d7084 100644 --- a/skills/hashicorp-aws-ami-builder/spec.yaml +++ b/skills/hashicorp-aws-ami-builder/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/packer/skills/aws-ami-builder" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-azure-image-builder/spec.yaml b/skills/hashicorp-azure-image-builder/spec.yaml index 5355278e..87d00976 100644 --- a/skills/hashicorp-azure-image-builder/spec.yaml +++ b/skills/hashicorp-azure-image-builder/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/packer/skills/azure-image-builder" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-azure-verified-modules/spec.yaml b/skills/hashicorp-azure-verified-modules/spec.yaml index 9c235937..c64086a6 100644 --- a/skills/hashicorp-azure-verified-modules/spec.yaml +++ b/skills/hashicorp-azure-verified-modules/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/azure-verified-modules" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-new-terraform-provider/spec.yaml b/skills/hashicorp-new-terraform-provider/spec.yaml index 7fa4322a..04b9846b 100644 --- a/skills/hashicorp-new-terraform-provider/spec.yaml +++ b/skills/hashicorp-new-terraform-provider/spec.yaml @@ -11,9 +11,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/new-terraform-provider" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-actions/spec.yaml b/skills/hashicorp-provider-actions/spec.yaml index 82f6453b..3c2d4fbc 100644 --- a/skills/hashicorp-provider-actions/spec.yaml +++ b/skills/hashicorp-provider-actions/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-actions" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-configuration/spec.yaml b/skills/hashicorp-provider-configuration/spec.yaml index 34841d12..841af587 100644 --- a/skills/hashicorp-provider-configuration/spec.yaml +++ b/skills/hashicorp-provider-configuration/spec.yaml @@ -15,9 +15,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-configuration" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-docs/spec.yaml b/skills/hashicorp-provider-docs/spec.yaml index 1f37a615..aeca23f0 100644 --- a/skills/hashicorp-provider-docs/spec.yaml +++ b/skills/hashicorp-provider-docs/spec.yaml @@ -12,9 +12,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-docs" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-ephemeral-resources/spec.yaml b/skills/hashicorp-provider-ephemeral-resources/spec.yaml index e2641885..2aa36eeb 100644 --- a/skills/hashicorp-provider-ephemeral-resources/spec.yaml +++ b/skills/hashicorp-provider-ephemeral-resources/spec.yaml @@ -13,9 +13,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-ephemeral-resources" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-framework-migration/spec.yaml b/skills/hashicorp-provider-framework-migration/spec.yaml index d805a69e..a954f573 100644 --- a/skills/hashicorp-provider-framework-migration/spec.yaml +++ b/skills/hashicorp-provider-framework-migration/spec.yaml @@ -13,9 +13,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-framework-migration" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-resources/spec.yaml b/skills/hashicorp-provider-resources/spec.yaml index cc41689b..55e78133 100644 --- a/skills/hashicorp-provider-resources/spec.yaml +++ b/skills/hashicorp-provider-resources/spec.yaml @@ -13,9 +13,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-resources" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-provider-test-patterns/spec.yaml b/skills/hashicorp-provider-test-patterns/spec.yaml index 29b609d4..0c4ba4ca 100644 --- a/skills/hashicorp-provider-test-patterns/spec.yaml +++ b/skills/hashicorp-provider-test-patterns/spec.yaml @@ -14,9 +14,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/provider-test-patterns" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-push-to-registry/spec.yaml b/skills/hashicorp-push-to-registry/spec.yaml index 2f29ef17..98aecdb8 100644 --- a/skills/hashicorp-push-to-registry/spec.yaml +++ b/skills/hashicorp-push-to-registry/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/packer/skills/push-to-registry" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" @@ -27,3 +27,5 @@ security: reason: "FP: matched Terraform HCL string-interpolation syntax (`${...}`) or GitHub Actions `secrets.*` references in documented configuration/CI examples (e.g. SKILL.md:38, SKILL.md:130) — standard HCL/CI syntax, not injected secrets." - rule_id: ATR_2026_00114 reason: "FP: matched placeholder credential values like `CLIENT_SECRET=\"your-client-secret\"` in documented example commands (e.g. SKILL.md:73) — literal placeholders, not real secrets." + - rule_id: LLM_SUPPLY_CHAIN_ATTACK + reason: "Accepted risk: documented `hashicorp/setup-packer@main` CI example (SKILL.md:125); operator accepts the mutable ref based on trust in the HashiCorp publisher." diff --git a/skills/hashicorp-refactor-module/spec.yaml b/skills/hashicorp-refactor-module/spec.yaml index b3dcb950..47c53945 100644 --- a/skills/hashicorp-refactor-module/spec.yaml +++ b/skills/hashicorp-refactor-module/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/refactor-module" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-run-acceptance-tests/spec.yaml b/skills/hashicorp-run-acceptance-tests/spec.yaml index 1982dded..9c949a0f 100644 --- a/skills/hashicorp-run-acceptance-tests/spec.yaml +++ b/skills/hashicorp-run-acceptance-tests/spec.yaml @@ -10,9 +10,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/run-acceptance-tests" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-terraform-policy/spec.yaml b/skills/hashicorp-terraform-policy/spec.yaml index db1a4159..39822947 100644 --- a/skills/hashicorp-terraform-policy/spec.yaml +++ b/skills/hashicorp-terraform-policy/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/terraform-policy" - version: "0.2.0" + version: "0.3.0" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-terraform-search-import/spec.yaml b/skills/hashicorp-terraform-search-import/spec.yaml index 84321ca6..b5dd30ab 100644 --- a/skills/hashicorp-terraform-search-import/spec.yaml +++ b/skills/hashicorp-terraform-search-import/spec.yaml @@ -10,9 +10,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/terraform-search-import" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-terraform-stacks/spec.yaml b/skills/hashicorp-terraform-stacks/spec.yaml index fa42b7e7..6cc78b81 100644 --- a/skills/hashicorp-terraform-stacks/spec.yaml +++ b/skills/hashicorp-terraform-stacks/spec.yaml @@ -11,9 +11,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/terraform-stacks" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-terraform-style-guide/spec.yaml b/skills/hashicorp-terraform-style-guide/spec.yaml index 82eea84b..7d12fc70 100644 --- a/skills/hashicorp-terraform-style-guide/spec.yaml +++ b/skills/hashicorp-terraform-style-guide/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/terraform-style-guide" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-terraform-test/spec.yaml b/skills/hashicorp-terraform-test/spec.yaml index a23265c9..c3743ac6 100644 --- a/skills/hashicorp-terraform-test/spec.yaml +++ b/skills/hashicorp-terraform-test/spec.yaml @@ -11,9 +11,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/terraform/skills/terraform-test" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" diff --git a/skills/hashicorp-windows-builder/spec.yaml b/skills/hashicorp-windows-builder/spec.yaml index 5f191628..6212865b 100644 --- a/skills/hashicorp-windows-builder/spec.yaml +++ b/skills/hashicorp-windows-builder/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/hashicorp/agent-skills" - ref: "6333093c37a318cb800d57a6de7d0877a9e048a4" # main as of 2026-08-10 + ref: "c2d65dfe492f74d360d35b859b88932222470bd8" # main as of 2026-08-10 path: "plugins/packer/skills/windows-builder" - version: "0.2.0" + version: "0.2.1" provenance: repository_uri: "https://github.com/hashicorp/agent-skills" @@ -22,7 +22,7 @@ security: - rule_id: MANIFEST_MISSING_LICENSE reason: "hashicorp/agent-skills is licensed MPL-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter." - rule_id: ATR_2026_00010 - reason: "FP: matched the documented Chocolatey bootstrap command `iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))` (SKILL.md:101) — the official Chocolatey install script run inside a Packer PowerShell provisioner to build a Windows image, not a hidden payload." + reason: "Risk accepted by maintainer (danbarr, 2026-09-18): matched the documented Chocolatey bootstrap command `iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))` (SKILL.md:108). This is Chocolatey's official HTTPS bootstrap script run inside a Packer PowerShell provisioner to build a Windows image; the mutable remote-script execution risk is explicit and accepted." - rule_id: ATR_2026_00063 reason: "FP: matched words like \"exfil\"/\"upload\"/\"encrypt\" in documentation prose — either warning against exfiltration (design-principles guidance) or describing legitimate upload/encryption features (HCP Packer registry push, state upload, disk encryption) (e.g. SKILL.md:47), not exfiltration code." - rule_id: ATR_2026_00064 @@ -31,3 +31,7 @@ security: reason: "FP: matched Terraform HCL string-interpolation syntax (`${...}`) or GitHub Actions `secrets.*` references in documented configuration/CI examples (e.g. SKILL.md:28, SKILL.md:70) — standard HCL/CI syntax, not injected secrets." - rule_id: ATR_2026_00091 reason: "FP: matched \"constructor\"/\"Constructor\" in Go code documentation describing struct initialization (e.g. SKILL.md:147), not an obfuscation pattern." + - rule_id: LLM_HARMFUL_CONTENT + reason: "Accepted risk: documented insecure/Basic WinRM bootstrap (SKILL.md:42-57) is required for Packer Windows builders; operator accepts it for temporary build targets with restricted network exposure." + - rule_id: LLM_SUPPLY_CHAIN_ATTACK + reason: "Risk accepted by maintainer (danbarr, 2026-09-18): the example uses Chocolatey's official HTTPS bootstrap script inside a Packer-built Windows image without pinning the script content or verifying a checksum. The supply-chain risk of executing that mutable vendor installer is explicit and accepted for this documented bootstrap workflow."