- Home
- Skills
- DevOps & Cloud
- terraform-iac-reviewer
More screenshots
Works with the AI tools you already use
Terraform Iac Reviewer
Review your Terraform and OpenTofu HCL for public S3 buckets, over-provisioned instances, local state files, missing...
Free
terraform-iac-reviewer
Example session with this skill installed
Review our Terraform configuration for the production VPC.
- Read your context and instructions
- Compiled the terraform-iac-reviewer
Critical (must fix before apply):
aws_security_group.web— Ingress rule allows0.0.0.0/0on port 22 (SSH).
Impact: Public SSH access to instances.
Fix: Restrict to bastion CIDR: cidr_blocks = ["10.0.1.0/24"]
aws_s3_bucket.logs— Noblock_public_aclsorblock_public_policy.
Impact: Bucket could be made public, exposing access logs.
Fix: Add block_public_acls = true, block_public_policy = true
Warning (should fix before merge):
aws_instance.api— Instance typem5.2xlargefor a service with avg CPU 12%.
Recommendation: Downsize to m5.large (~$100/month savings)
aws_s3_bucket.logs— No lifecycle rule. Recommendation: Addexpiration { days = 90 }for log retentionSuggestion:
module.vpc— Missingdescriptionoutput for the VPC ID. Add for documentation.
Connects securely to your tools. The creator never sees your data.
About this skill
Review your Terraform and OpenTofu HCL for public S3 buckets, over-provisioned instances, local state files, missing IAM boundaries, and 40+ provider-specific checks across AWS, Azure, and GCP.
The Problem
Your team manages 150 Terraform resources across AWS and GCP. A junior engineer opens a PR adding an S3 bucket with acl = "public-read" — the default behavior in some example templates. The PR gets approved because the reviewer focused on the module structure, not the security implications. Two weeks later, a security scan flags the bucket containing PII data as publicly accessible. The Terraform review gap is real: HCL is dense, provider-specific, and the security/cost implications of a resource configuration are rarely obvious from reading the code alone.
What You Get
- Security audit — checks every resource against a provider-specific security checklist: public exposure (S3, security groups, NSGs), unencrypted resources (EBS, RDS, storage accounts), overly permissive IAM (wildcard actions, broad ARNs), missing logging (CloudTrail, Activity Log), hardcoded secrets, and open network access (0.0.0.0/0 ingress)
- Cost analysis — identifies over-provisioned instances, missing lifecycle/expiration rules, unreserved capacity (on-demand where reserved/saves 40-70%), orphaned resources (unattached EBS, elastic IPs), and cross-region data transfer costs
- State and drift risk — flags local state files, missing state locking (DynamoDB/blob lease), no state versioning, sensitive data in state files, and workspace misuse (multiple environments in single state)
- Best-practice compliance — validates module structure, variable validation blocks, provider version pinning, naming conventions, mandatory tags, output descriptions, and module documentation
- terraform plan analysis — when given plan output, analyzes resource additions/modifications/deletions, identifies force-new replacements that cause downtime, and detects drift between desired and actual state
Why This Beats Prompting It Yourself
When you ask an agent to "review my Terraform," it checks syntax and module structure but misses provider-specific security requirements: that aws_s3_bucket without block_public_acls = true is a data exposure risk, that aws_iam_policy with "Action": "*" violates least-privilege, or that terraform.tfstate stored locally without DynamoDB locking means concurrent applies will corrupt state. This skill encodes 40+ provider-specific checks that require deep knowledge of AWS, Azure, and GCP security models — knowledge that general-purpose prompts don't have.
Example Session
You: Review our Terraform configuration for the production VPC.
Agent: Critical (must fix before apply):
aws_security_group.web— Ingress rule allows0.0.0.0/0on port 22 (SSH). Impact: Public SSH access to instances. Fix: Restrict to bastion CIDR:cidr_blocks = ["10.0.1.0/24"]aws_s3_bucket.logs— Noblock_public_aclsorblock_public_policy. Impact: Bucket could be made public, exposing access logs. Fix: Addblock_public_acls = true, block_public_policy = trueWarning (should fix before merge):
aws_instance.api— Instance typem5.2xlargefor a service with avg CPU 12%. Recommendation: Downsize tom5.large(~$100/month savings)aws_s3_bucket.logs— No lifecycle rule. Recommendation: Addexpiration { days = 90 }for log retentionSuggestion:
module.vpc— Missingdescriptionoutput for the VPC ID. Add for documentation.
Use Cases
- Reviewing Terraform PRs before merge to catch security misconfigurations that scanners miss
- Auditing an existing Terraform-managed infrastructure for cost optimization opportunities
- Analyzing
terraform planoutput to identify force-new replacements that will cause downtime - Enforcing tagging strategy and naming conventions across a multi-team Terraform codebase
- Validating state management practices (remote backend, locking, versioning) before production deployment
Known Limitations
The review is static analysis — it cannot detect runtime misconfigurations (e.g., an S3 bucket policy that was modified outside Terraform). Cost analysis estimates are based on list pricing and don't account for reserved instance discounts or enterprise agreements. The reviewer covers AWS, Azure, and GCP but does not support other providers (DigitalOcean, Alibaba Cloud) in this version.
Tags: terraform iac security cost-optimization aws azure gcp infrastructure
Version: 1.0.0
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
2 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 4 months ago
- Free to download with an account