- Home
- Skills
- DevOps & Cloud
- Infra Drift & Cost Sentinel
More screenshots
Works with the AI tools you already use
Infra Drift & Cost Sentinel
Catches security drift, cost leaks, and state drift in your Terraform before you apply — with a prioritized fix list, not just a wall of warnings.
$12
Infra Drift & Cost Sentinel
Example session with this skill installed
Here's my Terraform for our app's infra — can you check it for security issues, wasted spend, or anything that looks like it drifted from what's actually deployed before I run apply?
- Read your context and instructions
- Compiled the infra drift
Stack summary: AWS Terraform project, 6 resources reviewed (S3, security group, EC2, EBS, RDS).
| Severity | Category | Resource | Issue | Fix |
|---|---|---|---|---|
| Critical | Security | aws_db_instance.main | publicly_accessible = true on a prod-named DB | Set publicly_accessible = false; access via VPC/bastion or SSM tunnel instead |
| Critical | Security | aws_s3_bucket_acl.logs_acl | acl = "public-read", no public-access-block resource present | Remove the ACL, add aws_s3_bucket_public_access_block with all four flags true |
| Critical | Security | aws_security_group.db_sg | Ingress on port 5432 open to 0.0.0.0/0 | Restrict cidr_blocks to the app tier's SG or VPC CIDR |
| High | Security | aws_db_instance.main | storage_encrypted = false | Set storage_encrypted = true (note: requires recreation — plan for a maintenance window) |
| High | Cost | aws_instance.web_dev | m5.4xlarge on a resource tagged Environment = dev | Right-size to t3.large/m5.large for dev workloads pending actual usage data |
| High | Cost | aws_ebs_volume.orphan | Volume defined with no aws_volume_attachment anywhere in the project | Confirm it's unused, then remove — orphaned EBS volumes bill indefinitely |
| Low | Hygiene | All resources | No tags/cost-allocation tags except web_dev | Add a consistent tagging block (Environment, Owner, CostCenter) so future cost tooling can attribute spend |
Top 3 actions:
- Lock down the DB — it's both public and unencrypted, the worst combination in this file.
- Close the security group's 5432 ingress to 0.0.0.0/0 before this ever reaches prod.
- Remove the public ACL on the logs bucket.
What wasn't checked: No terraform plan or state file was provided, so state-drift checks (manual changes, unexpected replace/destroy) couldn't run — only code-level checks. Sending a terraform plan -out=plan.tfplan output would sharpen that section.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most linters tell you what's wrong. This skill tells you what actually matters and in what order.
Feed it your Terraform files, a terraform plan output, or a CloudFormation/Pulumi template. It runs three passes — security drift (public buckets, open security groups, unencrypted storage, overly broad IAM), cost leaks (oversized dev instances, orphaned volumes, missing lifecycle policies), and state drift (unexpected replace/destroy, manual console changes not reflected in code) — then hands back a severity-ranked findings table with a real one-line fix for each issue, plus a "top 3 actions" callout.
No generic advice, no padded findings to look thorough — if something's fine, it says so. Built for AWS-first stacks with GCP/Azure pattern coverage included.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 22 days ago
- Passed all security checks, Safe to install