SI

senaykt/iac-security-scan-skills

Developer tools
48 stars 品質 55 トレンド 55

iac security scan skills for your AI workflows

概要

AI-powered security assessment for Infrastructure-as-Code. Drop this into any Terraform or CloudFormation project, tell your AI agent to scan, and get a prioritized security report with attack paths and compliance mappings. Works with , , , , and — no plugins, no API keys, no installation. 1. Copy this repo into your Terraform project root: 4. Read findings in the terminal, open iac-scan/report.html, or import iac-scan/findings.csv. The scanner runs in three steps, orchestrated by AGENTS.md (or CLAUDE.md for Claude Code): The iac-analysis skill maps the entire repository: technology stack, environments, resource inventory, architecture patterns, internet exposure points, trust boundaries, and cross-account relationships. It also produces optimization tables in a iac-scan/analysis.md (≤ 120 lines — no full JSON graph dumps): - — maps each IaC file to the downstream skills that need it. - — skips irrelevant domain skills entirely.

README

IaC Security Scanner

AI-powered security assessment for Infrastructure-as-Code. Drop this into any Terraform or CloudFormation project, tell your AI agent to scan, and get a prioritized security report with attack paths and compliance mappings.

Works with Cursor, Claude Code, Opencode, Codex CLI, and Windsurf — no plugins, no API keys, no installation.

Quick Start

  1. Copy this repo into your Terraform project root:
cp -r iac-security-scanner-skills/{AGENTS.md,CLAUDE.md,.agents,.claude,.cursor} ./
  1. Open the project in your AI IDE.

  2. Tell the agent:

Run IaC security scan
  1. Read findings in the terminal, open iac-scan/report.html, or import iac-scan/findings.csv.

How It Works

The scanner runs in three steps, orchestrated by AGENTS.md (or CLAUDE.md for Claude Code):

Step 1                    Step 2 (parallel)              Step 2.5              Step 3
┌──────────────┐    ┌──────────────────────────┐    ┌─────────────────┐    ┌──────────────┐
│              │    │  iac-iam                 │    │                 │    │              │
│              │    │  iac-network             │    │                 │    │              │
│ iac-analysis ├───►│  iac-storage             ├───►│ iac-attack-chain├───►│  iac-report  │
│              │    │  iac-secrets             │    │                 │    │              │
│              │    │  iac-logging-monitoring  │    │                 │    │              │
│              │    │  iac-serverless          │    │                 │    │              │
└──────────────┘    └──────────────────────────┘    └─────────────────┘    └──────────────┘
  analysis.md         *-results.md                   attack-chain.md        report.html + CSV

Step 1 — Codebase Analysis

The iac-analysis skill maps the entire repository: technology stack, environments, resource inventory, architecture patterns, internet exposure points, trust boundaries, and cross-account relationships.

It also produces optimization tables in a compact iac-scan/analysis.md (≤ 120 lines — no full JSON graph dumps):

  • File Routing — maps each IaC file to the downstream skills that need it.
  • Recommended Skills — skips irrelevant domain skills entirely.
  • Secrets File List — for fast/scoped scans, lists only IaC/CI/CD/env files for iac-secrets (full scan uses all files).

Step 2 — Security Analysis (parallel)

Domain-specific skills run in parallel. Each skill receives only the files routed to it and produces deep, context-aware findings — not shallow linting.

Skill What it detects
iac-iam Privilege escalation paths, wildcard permissions, dangerous trust relationships, PassRole abuse, cross-account trust, lateral movement chains
iac-network Public exposure, VPC segmentation gaps, security group misconfigurations, unrestricted egress, missing VPC endpoints
iac-storage Unencrypted data stores, public S3 buckets, missing backup/DR, ransomware readiness gaps, dangerous data access patterns, data classification issues
iac-secrets Hardcoded credentials, leaked API keys, state file risks, CI/CD secret exposure, plaintext passwords in environment variables
iac-logging-monitoring CloudTrail gaps, missing GuardDuty, detection blind spots, forensic readiness issues, alerting pipeline gaps
iac-serverless Unauthenticated Lambda URLs, API Gateway misconfigurations, event injection, denial-of-wallet risks, overprivileged execution roles

Step 2.5 — Attack Chain Correlation

After all Step 2 skills complete, the iac-attack-chain skill reads all domain findings and constructs composite, cross-domain attack paths. It identifies internet-to-admin compromise paths, ransomware propagation chains, data exfiltration routes, and stealthy persistence opportunities. It performs minimum-cut analysis to find the smallest set of fixes that breaks the most attack paths — the highest-ROI fix list.

Step 3 — Report Generation

The iac-report skill deduplicates, prioritizes, and outputs findings in three formats: terminal table (printed to stdout), CSV (iac-scan/findings.csv), and self-contained HTML (iac-scan/report.html).

Why use this scanner

Built for teams that want deep IaC security reasoning without running the full pipeline on every PR. Scope scales with what you need — not “run everything every time.”

Scan modes

When Command
PR / quick check Run fast IaC scan
One area changed (e.g. IAM only) Scan only IAM or Run IAM analyzer
Two domains + chains Scan only IAM and network
Release / quarterly review Run IaC security scan
Re-report only Generate security report (reads existing iac-scan/)

Pipeline optimizations

  • File routing — Step 1 maps each IaC file to the domain skills that need it. Step 2 agents do not re-read the entire repo; iac-secrets is the only skill that may see all files on a full scan (and uses a narrower list on fast/scoped runs).
  • Skip irrelevant skills — Recommended Skills in analysis.md avoids running domains with no resources (e.g. no Lambda → skip serverless).
  • Compact artifacts — analysis.md ≤ 120 lines (no full JSON graph dumps). Each *-results.md ≤ 150 lines; findings capped at 8 lines each so downstream attack-chain and report steps stay small.
  • Fast mode — One ~175-line skill instead of nine separate skills (~5.4K lines). Single pass, High/Critical only, no attack-chain step.
  • Scoped scans — Run only the domains you care about; attack-chain runs only when 2+ domains are selected.
  • Examples not loaded — examples/ under each skill is documentation only; agents are not instructed to load it during scans.
  • Incremental re-runs — If iac-scan/analysis.md or *-results.md already exist, orchestration can skip completed steps; regenerate HTML/CSV without re-scanning.

What you get that linters miss

  • Cross-domain attack chains — internet → workload → IAM → data paths no single-domain tool sees.
  • Minimum-cut fixes — smallest set of changes that breaks the most chains.
  • Confidence scores (0.0–1.0) — confirmed IaC evidence vs inferred/heuristic findings.
  • Exploitability and blast radius — not just “policy has *”.
  • Detection blind spots — logging/monitoring gaps tied to exposed or privileged resources.

Commands

Full Scan

Command What it does
Run IaC security scan Full pipeline — analysis → domain skills → attack chains → report
Run IaC security scan on the terraform/ directory Full scan on a specific subdirectory

Fast Scan (lite mode)

Command What it does
Run fast IaC scan Single-pass analysis, High/Critical only, compact HTML report

Fast mode loads a single iac-fast-scan/SKILL.md (~150 lines) instead of 9 separate skills (~7000 lines total). All 6 domains are checked in one pass — no separate steps, no attack chain correlation, no architecture diagram. Produces iac-scan/fast-results.md + iac-scan/fast-report.html. Ideal for quick checks and PR reviews.

Scoped Scan (selected domains only)

Command What it does
Scan only IAM and network Runs only IAM + network skills, skips the rest
Scan only IAM, storage, secrets Runs only the 3 specified skills

Valid domain names: IAM, network, storage, secrets, logging, serverless. Step 1 (analysis) always runs. Attack chain correlation runs only if 2+ domains are selected. The report notes which domains were excluded.

Individual Analyzers

Run a single domain skill. Step 1 (analysis) runs automatically if needed.

Command What it runs
Run IAM analyzer IAM policy analysis, privilege escalation, trust chains
Run network analyzer Network exposure, segmentation, reachability
Run storage analyzer S3, RDS, DynamoDB, encryption, backup/DR
Run secrets analyzer Hardcoded credentials, secret management
Run logging analyzer CloudTrail, GuardDuty, detection coverage
Run serverless analyzer Lambda, API Gateway, event-driven risks

Post-Scan

Command What it does
Run attack chain analysis Cross-domain correlation from existing skill results
Generate security report Terminal table + HTML + CSV from existing iac-scan/ results (skips Steps 1–2)

Output

All results are written to the iac-scan/ directory:

iac-scan/
├── analysis.md                   # Repository intelligence (Step 1)
├── iam-results.md                # IAM findings
├── network-results.md            # Network findings
├── storage-results.md            # Storage & data findings
├── secrets-results.md            # Secrets findings
├── logging-monitoring-results.md # Logging & monitoring findings
├── serverless-results.md         # Serverless findings
├── attack-chain-results.md       # Cross-domain attack chains (Step 2.5)
├── findings.csv                  # CSV export (Step 3)
├── report.html                   # HTML report (Step 3)
└── architecture-diagram.html     # Architecture visualization (Step 3)

Add iac-scan/ to your .gitignore — scan results should not be committed.

Supported Project Layouts

The scanner handles all common Terraform project structures:

Layout Example
Flat files at root main.tf, vpc.tf, iam.tf in project root
Per-environment directories envs/prod/, envs/staging/, envs/dev/
Per-account directories accounts/prod-app/, accounts/security/, accounts/log-archive/
Terragrunt landing zone Layered account.hcl / region.hcl / env.hcl
Per-service repo App code + infra/ or terraform/ subdirectory
CDK app cdk.json, lib/, bin/, synthesized CloudFormation
Serverless Framework / SAM serverless.yml, template.yaml
CloudFormation StackSets Multi-region / multi-account stacks
Atlantis-managed atlantis.yaml with project list
Monorepo Multiple stacks, modules, and environments in one repo

IDE Compatibility

Skills are stored in three directories for cross-IDE compatibility:

Directory IDE
.agents/skills/ Opencode, Codex CLI, Windsurf
.claude/skills/ Claude Code
.cursor/skills/ Cursor

All three contain the same 9 skills + 1 fast-scan skill. The orchestration file (AGENTS.md or CLAUDE.md) tells the agent where to find them.

Skills

Skill Lines Focus
iac-analysis ~715 Repository intelligence; compact analysis.md output (≤120 lines)
iac-iam ~630 IAM policy analysis, privilege escalation, trust chains
iac-network ~640 Network exposure, segmentation, reachability
iac-storage ~750 S3, RDS, DynamoDB, encryption, backup/DR, ransomware readiness
iac-secrets ~285 Credential detection, secret management analysis
iac-logging-monitoring ~620 Detection coverage, forensic readiness, alerting gaps
iac-serverless ~640 Serverless attack surface, event-driven risks
iac-attack-chain ~790 Cross-domain attack path correlation, minimum-cut analysis
iac-report ~180 Deduplication, prioritization, terminal + CSV + HTML output
iac-fast-scan ~175 All-in-one lite scan (fast mode only)

Most skills also have an examples/ directory with reference outputs and JSON schemas. These are not loaded during scans — they serve as documentation.

What This Is NOT

This is not a linter. It does not flag every * in an IAM policy or every missing tag. It reasons about:

  • Attack paths — “Can an attacker chain these findings to go from internet to admin?”
  • Exploitability — “Is this actually exploitable, or is it theoretical?”
  • Blast radius — “If this is exploited, what else is affected?”
  • Detection visibility — “Would we even notice if this was exploited?”
  • Confidence — “Is this definitely there (0.95) or probably there (0.55)?”
  • Architecture — “What does the infrastructure actually look like?” (inferred diagram)
  • Business impact — “What does this mean in business terms?”
  • Fix priority — “What should we fix first to break the most attack paths?”

Every finding includes a confidence score (0.0–1.0) that distinguishes confirmed issues (direct IaC evidence, score >= 0.9) from inferred ones (heuristic-based, unresolved references, score 0.3–0.7). Low-confidence findings are dampened in the priority scoring — they stay visible but don’t dominate the report.

Primary Focus

  • Cloud: AWS
  • IaC: Terraform, CloudFormation, SAM, CDK, Serverless Framework
  • Compliance: CIS AWS Foundations, NIST 800-53, PCI DSS v4.0, SOC 2, HIPAA, MITRE ATT&CK

License

MIT

View this README on GitHub

推奨ツール

別のキーワードを試すか、フィルタを外してください。

インストール

npx skillfish add senaykt/iac-security-scan-skills