iac security scan skills for your AI workflows
概要
AI-powered security assessment for Infrastructure-as-Code. Drop this into any Terraform or CloudFormation project, tell your AI agent to scan, and get a prioritized security report with attack paths and compliance mappings. Works with , , , , and — no plugins, no API keys, no installation. 1. Copy this repo into your Terraform project root: 4. Read findings in the terminal, open iac-scan/report.html, or import iac-scan/findings.csv. The scanner runs in three steps, orchestrated by AGENTS.md (or CLAUDE.md for Claude Code): The iac-analysis skill maps the entire repository: technology stack, environments, resource inventory, architecture patterns, internet exposure points, trust boundaries, and cross-account relationships. It also produces optimization tables in a iac-scan/analysis.md (≤ 120 lines — no full JSON graph dumps): - — maps each IaC file to the downstream skills that need it. - — skips irrelevant domain skills entirely.
README
IaC Security Scanner
AI-powered security assessment for Infrastructure-as-Code. Drop this into any Terraform or CloudFormation project, tell your AI agent to scan, and get a prioritized security report with attack paths and compliance mappings.
Works with Cursor, Claude Code, Opencode, Codex CLI, and Windsurf — no plugins, no API keys, no installation.
Quick Start
- Copy this repo into your Terraform project root:
cp -r iac-security-scanner-skills/{AGENTS.md,CLAUDE.md,.agents,.claude,.cursor} ./
-
Open the project in your AI IDE.
-
Tell the agent:
Run IaC security scan
- Read findings in the terminal, open
iac-scan/report.html, or importiac-scan/findings.csv.
How It Works
The scanner runs in three steps, orchestrated by AGENTS.md (or CLAUDE.md for Claude Code):
Step 1 Step 2 (parallel) Step 2.5 Step 3
┌──────────────┐ ┌──────────────────────────┐ ┌─────────────────┐ ┌──────────────┐
│ │ │ iac-iam │ │ │ │ │
│ │ │ iac-network │ │ │ │ │
│ iac-analysis ├───►│ iac-storage ├───►│ iac-attack-chain├───►│ iac-report │
│ │ │ iac-secrets │ │ │ │ │
│ │ │ iac-logging-monitoring │ │ │ │ │
│ │ │ iac-serverless │ │ │ │ │
└──────────────┘ └──────────────────────────┘ └─────────────────┘ └──────────────┘
analysis.md *-results.md attack-chain.md report.html + CSV
Step 1 — Codebase Analysis
The iac-analysis skill maps the entire repository: technology stack, environments, resource inventory, architecture patterns, internet exposure points, trust boundaries, and cross-account relationships.
It also produces optimization tables in a compact iac-scan/analysis.md (≤ 120 lines — no full JSON graph dumps):
- File Routing — maps each IaC file to the downstream skills that need it.
- Recommended Skills — skips irrelevant domain skills entirely.
- Secrets File List — for fast/scoped scans, lists only IaC/CI/CD/env files for
iac-secrets(full scan uses all files).
Step 2 — Security Analysis (parallel)
Domain-specific skills run in parallel. Each skill receives only the files routed to it and produces deep, context-aware findings — not shallow linting.
| Skill | What it detects |
|---|---|
| iac-iam | Privilege escalation paths, wildcard permissions, dangerous trust relationships, PassRole abuse, cross-account trust, lateral movement chains |
| iac-network | Public exposure, VPC segmentation gaps, security group misconfigurations, unrestricted egress, missing VPC endpoints |
| iac-storage | Unencrypted data stores, public S3 buckets, missing backup/DR, ransomware readiness gaps, dangerous data access patterns, data classification issues |
| iac-secrets | Hardcoded credentials, leaked API keys, state file risks, CI/CD secret exposure, plaintext passwords in environment variables |
| iac-logging-monitoring | CloudTrail gaps, missing GuardDuty, detection blind spots, forensic readiness issues, alerting pipeline gaps |
| iac-serverless | Unauthenticated Lambda URLs, API Gateway misconfigurations, event injection, denial-of-wallet risks, overprivileged execution roles |
Step 2.5 — Attack Chain Correlation
After all Step 2 skills complete, the iac-attack-chain skill reads all domain findings and constructs composite, cross-domain attack paths. It identifies internet-to-admin compromise paths, ransomware propagation chains, data exfiltration routes, and stealthy persistence opportunities. It performs minimum-cut analysis to find the smallest set of fixes that breaks the most attack paths — the highest-ROI fix list.
Step 3 — Report Generation
The iac-report skill deduplicates, prioritizes, and outputs findings in three formats: terminal table (printed to stdout), CSV (iac-scan/findings.csv), and self-contained HTML (iac-scan/report.html).
Why use this scanner
Built for teams that want deep IaC security reasoning without running the full pipeline on every PR. Scope scales with what you need — not “run everything every time.”
Scan modes
| When | Command |
|---|---|
| PR / quick check | Run fast IaC scan |
| One area changed (e.g. IAM only) | Scan only IAM or Run IAM analyzer |
| Two domains + chains | Scan only IAM and network |
| Release / quarterly review | Run IaC security scan |
| Re-report only | Generate security report (reads existing iac-scan/) |
Pipeline optimizations
- File routing — Step 1 maps each IaC file to the domain skills that need it. Step 2 agents do not re-read the entire repo;
iac-secretsis the only skill that may see all files on a full scan (and uses a narrower list on fast/scoped runs). - Skip irrelevant skills —
Recommended Skillsinanalysis.mdavoids running domains with no resources (e.g. no Lambda → skip serverless). - Compact artifacts —
analysis.md≤ 120 lines (no full JSON graph dumps). Each*-results.md≤ 150 lines; findings capped at 8 lines each so downstream attack-chain and report steps stay small. - Fast mode — One ~175-line skill instead of nine separate skills (~5.4K lines). Single pass, High/Critical only, no attack-chain step.
- Scoped scans — Run only the domains you care about; attack-chain runs only when 2+ domains are selected.
- Examples not loaded —
examples/under each skill is documentation only; agents are not instructed to load it during scans. - Incremental re-runs — If
iac-scan/analysis.mdor*-results.mdalready exist, orchestration can skip completed steps; regenerate HTML/CSV without re-scanning.
What you get that linters miss
- Cross-domain attack chains — internet → workload → IAM → data paths no single-domain tool sees.
- Minimum-cut fixes — smallest set of changes that breaks the most chains.
- Confidence scores (0.0–1.0) — confirmed IaC evidence vs inferred/heuristic findings.
- Exploitability and blast radius — not just “policy has
*”. - Detection blind spots — logging/monitoring gaps tied to exposed or privileged resources.
Commands
Full Scan
| Command | What it does |
|---|---|
Run IaC security scan |
Full pipeline — analysis → domain skills → attack chains → report |
Run IaC security scan on the terraform/ directory |
Full scan on a specific subdirectory |
Fast Scan (lite mode)
| Command | What it does |
|---|---|
Run fast IaC scan |
Single-pass analysis, High/Critical only, compact HTML report |
Fast mode loads a single iac-fast-scan/SKILL.md (~150 lines) instead of 9 separate skills (~7000 lines total). All 6 domains are checked in one pass — no separate steps, no attack chain correlation, no architecture diagram. Produces iac-scan/fast-results.md + iac-scan/fast-report.html. Ideal for quick checks and PR reviews.
Scoped Scan (selected domains only)
| Command | What it does |
|---|---|
Scan only IAM and network |
Runs only IAM + network skills, skips the rest |
Scan only IAM, storage, secrets |
Runs only the 3 specified skills |
Valid domain names: IAM, network, storage, secrets, logging, serverless. Step 1 (analysis) always runs. Attack chain correlation runs only if 2+ domains are selected. The report notes which domains were excluded.
Individual Analyzers
Run a single domain skill. Step 1 (analysis) runs automatically if needed.
| Command | What it runs |
|---|---|
Run IAM analyzer |
IAM policy analysis, privilege escalation, trust chains |
Run network analyzer |
Network exposure, segmentation, reachability |
Run storage analyzer |
S3, RDS, DynamoDB, encryption, backup/DR |
Run secrets analyzer |
Hardcoded credentials, secret management |
Run logging analyzer |
CloudTrail, GuardDuty, detection coverage |
Run serverless analyzer |
Lambda, API Gateway, event-driven risks |
Post-Scan
| Command | What it does |
|---|---|
Run attack chain analysis |
Cross-domain correlation from existing skill results |
Generate security report |
Terminal table + HTML + CSV from existing iac-scan/ results (skips Steps 1–2) |
Output
All results are written to the iac-scan/ directory:
iac-scan/
├── analysis.md # Repository intelligence (Step 1)
├── iam-results.md # IAM findings
├── network-results.md # Network findings
├── storage-results.md # Storage & data findings
├── secrets-results.md # Secrets findings
├── logging-monitoring-results.md # Logging & monitoring findings
├── serverless-results.md # Serverless findings
├── attack-chain-results.md # Cross-domain attack chains (Step 2.5)
├── findings.csv # CSV export (Step 3)
├── report.html # HTML report (Step 3)
└── architecture-diagram.html # Architecture visualization (Step 3)
Add iac-scan/ to your .gitignore — scan results should not be committed.
Supported Project Layouts
The scanner handles all common Terraform project structures:
| Layout | Example |
|---|---|
| Flat files at root | main.tf, vpc.tf, iam.tf in project root |
| Per-environment directories | envs/prod/, envs/staging/, envs/dev/ |
| Per-account directories | accounts/prod-app/, accounts/security/, accounts/log-archive/ |
| Terragrunt landing zone | Layered account.hcl / region.hcl / env.hcl |
| Per-service repo | App code + infra/ or terraform/ subdirectory |
| CDK app | cdk.json, lib/, bin/, synthesized CloudFormation |
| Serverless Framework / SAM | serverless.yml, template.yaml |
| CloudFormation StackSets | Multi-region / multi-account stacks |
| Atlantis-managed | atlantis.yaml with project list |
| Monorepo | Multiple stacks, modules, and environments in one repo |
IDE Compatibility
Skills are stored in three directories for cross-IDE compatibility:
| Directory | IDE |
|---|---|
.agents/skills/ |
Opencode, Codex CLI, Windsurf |
.claude/skills/ |
Claude Code |
.cursor/skills/ |
Cursor |
All three contain the same 9 skills + 1 fast-scan skill. The orchestration file (AGENTS.md or CLAUDE.md) tells the agent where to find them.
Skills
| Skill | Lines | Focus |
|---|---|---|
iac-analysis |
~715 | Repository intelligence; compact analysis.md output (≤120 lines) |
iac-iam |
~630 | IAM policy analysis, privilege escalation, trust chains |
iac-network |
~640 | Network exposure, segmentation, reachability |
iac-storage |
~750 | S3, RDS, DynamoDB, encryption, backup/DR, ransomware readiness |
iac-secrets |
~285 | Credential detection, secret management analysis |
iac-logging-monitoring |
~620 | Detection coverage, forensic readiness, alerting gaps |
iac-serverless |
~640 | Serverless attack surface, event-driven risks |
iac-attack-chain |
~790 | Cross-domain attack path correlation, minimum-cut analysis |
iac-report |
~180 | Deduplication, prioritization, terminal + CSV + HTML output |
iac-fast-scan |
~175 | All-in-one lite scan (fast mode only) |
Most skills also have an examples/ directory with reference outputs and JSON schemas. These are not loaded during scans — they serve as documentation.
What This Is NOT
This is not a linter. It does not flag every * in an IAM policy or every missing tag. It reasons about:
- Attack paths — “Can an attacker chain these findings to go from internet to admin?”
- Exploitability — “Is this actually exploitable, or is it theoretical?”
- Blast radius — “If this is exploited, what else is affected?”
- Detection visibility — “Would we even notice if this was exploited?”
- Confidence — “Is this definitely there (0.95) or probably there (0.55)?”
- Architecture — “What does the infrastructure actually look like?” (inferred diagram)
- Business impact — “What does this mean in business terms?”
- Fix priority — “What should we fix first to break the most attack paths?”
Every finding includes a confidence score (0.0–1.0) that distinguishes confirmed issues (direct IaC evidence, score >= 0.9) from inferred ones (heuristic-based, unresolved references, score 0.3–0.7). Low-confidence findings are dampened in the priority scoring — they stay visible but don’t dominate the report.
Primary Focus
- Cloud: AWS
- IaC: Terraform, CloudFormation, SAM, CDK, Serverless Framework
- Compliance: CIS AWS Foundations, NIST 800-53, PCI DSS v4.0, SOC 2, HIPAA, MITRE ATT&CK
License
MIT
推奨ツール
別のキーワードを試すか、フィルタを外してください。
インストール
npx skillfish add senaykt/iac-security-scan-skills