Iac Scan

Infrastructure-as-Code security scan for changed deploy config — Dockerfiles, docker-compose, Terraform, Kubernetes/Helm, and CI/CD workflows. Flags misconfigurations and exposed secrets (root containers, open ingress, wildcard IAM, privileged pods, untrusted CI triggers). Static diff-scoped analysis (safe to auto-run); uses tfsec/checkov/hadolint/actionlint when present. Use when asked to "scan infra", "IaC scan", "check the Dockerfile/terraform/k8s", "CI security", or after changing deploy/infra config.

ariadoss 10b9df5 5.8 KB Updated

File contents

ariadoss/superskills/tree/main/skills/iac-scan commit 10b9df51fb

Frequently asked questions

npx skillmds@latest add ariadoss/iac-scan