BoundBench

Terraform MCP Server

HashiCorp MCP server for Terraform Registry and HCP Terraform workspace operations

github.com/hashicorp/terraform-mcp-server · 2026-10-03 · 1d9a2e0

Defense-in-depth score

4.3 / 10

Minimal

Despite the documentation saying only registry tools are on by default, the code enables every tool group, so giving the server a Terraform token hands the model write access to workspaces, variables, teams and access grants across every organization that token reaches. Delete and apply tools sit behind ENABLE_TF_OPERATIONS, though enforcement of that gate does not cover every path, and the model can point a workspace at any repository and run its code with attached credentials. Handling of sensitive values on the logging path is also not locked down. Run it with --toolsets=registry or a read-only, narrowly scoped team token.

Key gaps (3)

  1. The default tool set exposes grant_team_access and add_team_member, letting a hijacked session raise its own team's access with the user's org-wide token. C1 · Identity & least privilege
  2. The model can create a workspace from any VCS repository, attach credential-bearing variable sets and queue a plan, running chosen code with those credentials, and can switch execution off the remote runners. C4 · Code-execution isolation
  3. Untrusted registry content reaches the model in the same session as sensitive reads and irreversible writes, with no server-side separation. C5 · Untrusted input blast radius

Criteria

C1 Identity & least privilege

Minimal 0.13 / 1.00

The server acts with one long-lived Terraform API token taken from TFE_TOKEN or, if that is unset, silently from the user's Terraform CLI credentials file. Every tool uses that same token for reads and writes, and in the default stdio mode there is no server-side authorization layer: whatever the token can do, the model can do. The token is typically a user token, so the agent holds the user's full HCP Terraform authority across organizations, and tools such as grant_team_access (including 'admin') and add_team_member let it widen access for its own team.

C2 Approval gates

Minimal 0.25 / 1.00

The server does not ask for approval itself; it relies on the host. It tags tools with read-only/destructive hints, and the deletes, force-unlock, run apply/discard and destroy runs are not registered unless the operator sets ENABLE_TF_OPERATIONS=true. But several powerful tools are tagged non-destructive (update_workspace, grant_team_access, add_team_member), there is no dry-run or read-only mode, and enforcement of the gate does not cover every path. The only 'confirm first' rule is a sentence in the server instructions.

C3 Tool & action scoping

Minimal 0.45 / 1.00

Tools are narrow, purpose-built wrappers over the HCP Terraform API (no shell, no generic HTTP), with typed parameters and some value checks (access levels, execution modes). But schema enums and page-size limits are advertised to the model rather than enforced, VCS repository identifiers are unrestricted, and the default enables every tool group once a token is present, so a misused tool reaches every workspace, team and variable set the token can touch.

C4 Code-execution isolation

Minimal 0.25 / 1.00

The server runs nothing locally, but its purpose is to trigger Terraform runs, and a Terraform plan executes provider and data-source code on HCP Terraform workers. The model can create a workspace backed by any repository the org's VCS connection can read, attach variable sets (often cloud credentials) and queue a plan, all without the destructive-operations switch. How those workers are isolated is outside this repo, and the model can also switch a workspace to self-hosted agent or local execution.

C5 Untrusted input blast radius

Minimal 0.07 / 1.00

The server returns raw third-party content (public registry provider and module documentation anyone can publish, plan and apply logs, run comments) as plain text with no marking of where it came from, and offers no read-only or no-egress mode. In the default configuration a hijacked host model can read secrets-bearing data, change access, delete variables and push changes to infrastructure through the same session, with nothing in the server separating untrusted input from those actions.

C6 Memory, context & configuration integrity

N/A · full credit 1.00 / 1.00

The server keeps no memory, vector store or persistent context, and loads no configuration from the working directory: settings come from environment variables and flags, credentials from the user-scope Terraform CLI file, and its instructions are compiled into the binary. Nothing the model reads can persist into later sessions through the server.

C7 Third-party extensions

N/A · full credit 1.00 / 1.00

The server loads no plugins, launches no other MCP servers and executes no downloaded code in its own process. Third-party Terraform providers and modules are only fetched and run by HCP Terraform workers, which is covered under code execution.

C8 Secrets & sensitive-data protection

Minimal 0.25 / 1.00

The API token is read from the environment or the user's Terraform credentials file, never returned to the model, and only a hash of it is kept for cache comparison. But sensitive values on the server's logging path are not fully protected. Plan JSON output, which can contain sensitive values, is returned to the model unredacted. Telemetry is off by default and content-free.

C9 Audit & traceability

Minimal 0.38 / 1.00

Every tool call is written to the server log with its name and arguments before it runs, through a middleware registered for all tools. The record is plain text by default, has no result status or caller identity in stdio mode, and goes to stderr where the host decides what to keep. HCP Terraform keeps its own audit trail, which is independent of this server.

C10 Limits & kill switch

Moderate 0.50 / 1.00

All tool calls pass a rate limiter (10 per second globally, 5 per second per session by default), and HTTP requests to the registry and HCP Terraform have a 10-second timeout with three retries. But registry pagination loops have no page limit, registry requests are not tied to the caller's cancellation, and runs the server starts keep executing on HCP Terraform after the session ends.