iac-security-review
Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). Use when reviewing IaC files for misconfigurations, overpermissioning, exposed resources, missing encryption, secrets in code, and supply chain risks. Covers CIS benchmarks and cloud security best practices.
How do I install this agent skill?
npx skills add https://github.com/owasp/secure-agent-playbook --skill iac-security-reviewIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides a procedural framework for an AI agent to perform security reviews of Infrastructure-as-Code (IaC) templates. It consists purely of instructional markdown content and does not contain any executable code, remote downloads, or malicious behavior.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
IaC Security Review
Review infrastructure-as-code for security risks by following the full procedure in plays/iac-security-review.md.
Steps
-
Detect IaC Type — Identify the infrastructure technology from file extensions and content:
.tf/.tofufiles → Terraform/OpenTofu (referencedata/secure-code-prompts/terraform.md)- Kubernetes manifests (apiVersion, kind: Deployment/Pod/Service) → Kubernetes (reference
data/secure-code-prompts/kubernetes.md) - CloudFormation templates (AWSTemplateFormatVersion, Resources with AWS::) → CloudFormation (reference
data/secure-code-prompts/cloudformation.md) - Helm charts (
Chart.yaml, templates/) → Kubernetes review with Helm-specific checks
-
Systematic Review by Security Domain (priority order):
- Identity & Access Management — Overly permissive policies, wildcard permissions, hardcoded credentials, privilege escalation paths
- Secrets Management — Hardcoded secrets, plaintext credentials, missing vault/secret manager integration
- Network Security — Open ingress (
0.0.0.0/0), unrestricted ports, missing segmentation, public exposure - Encryption — Missing encryption at rest/in transit, weak algorithms, default keys
- Storage Security — Public buckets, unencrypted volumes, missing versioning
- Logging & Monitoring — Missing audit trails, disabled CloudTrail/audit logging
- Resource Exposure — Databases, admin interfaces, APIs exposed to internet
- Supply Chain — Unpinned versions, untrusted sources, unverified modules/images
- Platform-Specific Risks — Terraform state exposure, K8s privileged containers, CFN nested stack integrity
-
Check Against Benchmarks — Validate configurations against:
- CIS Benchmarks (AWS/Azure/GCP/Kubernetes)
- Cloud provider security best practices
- Pod Security Standards (for Kubernetes)
-
Produce Findings — For each finding: cite resource path, explain the misconfiguration, describe attack scenario, provide fixed code example, rate severity.
Output
Findings sorted by severity using templates/finding.md format, summary with severity counts, and secure configuration improvements section.
References
- CIS Benchmarks (AWS, Azure, GCP, Kubernetes)
- OWASP Infrastructure Security Cheat Sheet
- NSA/CISA Kubernetes Hardening Guide
- Cloud provider Well-Architected Frameworks
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/owasp/secure-agent-playbook/iac-security-review">View iac-security-review on skillZs</a>