More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Terraform Iac Reviewer

    2

    Review your Terraform and OpenTofu HCL for public S3 buckets, over-provisioned instances, local state files, missing...

    Free

    2 installsSecurity scanned
    terraform-iac-reviewer

    terraform-iac-reviewer

    Example session with this skill installed

    Review our Terraform configuration for the production VPC.

    • Read your context and instructions
    • Compiled the terraform-iac-reviewer

    Critical (must fix before apply):

    • aws_security_group.web — Ingress rule allows 0.0.0.0/0 on port 22 (SSH).

    Impact: Public SSH access to instances.

    Fix: Restrict to bastion CIDR: cidr_blocks = ["10.0.1.0/24"]

    • aws_s3_bucket.logs — No block_public_acls or block_public_policy.

    Impact: Bucket could be made public, exposing access logs.

    Fix: Add block_public_acls = true, block_public_policy = true

    Warning (should fix before merge):

    • aws_instance.api — Instance type m5.2xlarge for a service with avg CPU 12%.

    Recommendation: Downsize to m5.large (~$100/month savings)

    • aws_s3_bucket.logs — No lifecycle rule. Recommendation: Add expiration { days = 90 } for log retention

    Suggestion:

    • module.vpc — Missing description output for the VPC ID. Add for documentation.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Review your Terraform and OpenTofu HCL for public S3 buckets, over-provisioned instances, local state files, missing IAM boundaries, and 40+ provider-specific checks across AWS, Azure, and GCP.

    The Problem

    Your team manages 150 Terraform resources across AWS and GCP. A junior engineer opens a PR adding an S3 bucket with acl = "public-read" — the default behavior in some example templates. The PR gets approved because the reviewer focused on the module structure, not the security implications. Two weeks later, a security scan flags the bucket containing PII data as publicly accessible. The Terraform review gap is real: HCL is dense, provider-specific, and the security/cost implications of a resource configuration are rarely obvious from reading the code alone.

    What You Get

    • Security audit — checks every resource against a provider-specific security checklist: public exposure (S3, security groups, NSGs), unencrypted resources (EBS, RDS, storage accounts), overly permissive IAM (wildcard actions, broad ARNs), missing logging (CloudTrail, Activity Log), hardcoded secrets, and open network access (0.0.0.0/0 ingress)
    • Cost analysis — identifies over-provisioned instances, missing lifecycle/expiration rules, unreserved capacity (on-demand where reserved/saves 40-70%), orphaned resources (unattached EBS, elastic IPs), and cross-region data transfer costs
    • State and drift risk — flags local state files, missing state locking (DynamoDB/blob lease), no state versioning, sensitive data in state files, and workspace misuse (multiple environments in single state)
    • Best-practice compliance — validates module structure, variable validation blocks, provider version pinning, naming conventions, mandatory tags, output descriptions, and module documentation
    • terraform plan analysis — when given plan output, analyzes resource additions/modifications/deletions, identifies force-new replacements that cause downtime, and detects drift between desired and actual state

    Why This Beats Prompting It Yourself

    When you ask an agent to "review my Terraform," it checks syntax and module structure but misses provider-specific security requirements: that aws_s3_bucket without block_public_acls = true is a data exposure risk, that aws_iam_policy with "Action": "*" violates least-privilege, or that terraform.tfstate stored locally without DynamoDB locking means concurrent applies will corrupt state. This skill encodes 40+ provider-specific checks that require deep knowledge of AWS, Azure, and GCP security models — knowledge that general-purpose prompts don't have.

    Example Session

    You: Review our Terraform configuration for the production VPC.

    Agent: Critical (must fix before apply):

    • aws_security_group.web — Ingress rule allows 0.0.0.0/0 on port 22 (SSH). Impact: Public SSH access to instances. Fix: Restrict to bastion CIDR: cidr_blocks = ["10.0.1.0/24"]
    • aws_s3_bucket.logs — No block_public_acls or block_public_policy. Impact: Bucket could be made public, exposing access logs. Fix: Add block_public_acls = true, block_public_policy = true

    Warning (should fix before merge):

    • aws_instance.api — Instance type m5.2xlarge for a service with avg CPU 12%. Recommendation: Downsize to m5.large (~$100/month savings)
    • aws_s3_bucket.logs — No lifecycle rule. Recommendation: Add expiration { days = 90 } for log retention

    Suggestion:

    • module.vpc — Missing description output for the VPC ID. Add for documentation.

    Use Cases

    • Reviewing Terraform PRs before merge to catch security misconfigurations that scanners miss
    • Auditing an existing Terraform-managed infrastructure for cost optimization opportunities
    • Analyzing terraform plan output to identify force-new replacements that will cause downtime
    • Enforcing tagging strategy and naming conventions across a multi-team Terraform codebase
    • Validating state management practices (remote backend, locking, versioning) before production deployment

    Known Limitations

    The review is static analysis — it cannot detect runtime misconfigurations (e.g., an S3 bucket policy that was modified outside Terraform). Cost analysis estimates are based on list pricing and don't account for reserved instance discounts or enterprise agreements. The reviewer covers AWS, Azure, and GCP but does not support other providers (DigitalOcean, Alibaba Cloud) in this version.


    Tags: terraform iac security cost-optimization aws azure gcp infrastructure

    Version: 1.0.0

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    2 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions