Infrastructure-as-code review
SkillFiles & storageSecurity review of infrastructure-as-code, Terraform, CloudFormation, Ansible, Kubernetes/Helm manifests. Load when reviewing IaC in a repo/PR, on .tf/.yaml/.yml infra files, or "review our Terraform". Signals: *.tf, cloudformation/*.yaml, playbooks, k8s manifests, Helm charts, module registries.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Infrastructure-as-code review skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-iac/SKILL.md and read by ahel’s review.
When it applies
Reviewing the code that provisions cloud/infra. IaC misconfigurations become real, exploitable
exposure the moment they apply — a single line can make a bucket public or an SG world-open — so
this pairs directly with the offensive cloud-* skills.
Why it works
IaC is declarative and repeatable: the same insecure default gets deployed everywhere it's
referenced. Scanning the definitions catches the exposure before it exists, and the patterns
(public access, 0.0.0.0/0, plaintext secrets, missing encryption/logging) are consistent across
providers.
Sinks & patterns (scan, then reason about blast radius)
- Public exposure: S3/GCS/Blob
acl = "public-read"/ public access blocks disabled; security groups / firewall rules0.0.0.0/0on 22/3389/DB ports; public RDS/ELB;publiclyAccessible=true. - Over-broad IAM:
Action:"*"/Resource:"*",iam:PassRolewildcards,AssumeRoletrust to"*", admin-equivalent managed policies attached broadly. - Secrets in code: hardcoded keys/passwords/tokens in
.tf/vars/playbooks; secrets committed in state or plan output;sensitive = falseon secret outputs. - Missing protections: encryption at rest/in transit off (EBS/S3/RDS/SNS), logging/audit disabled (CloudTrail, flow logs, GCP audit), no MFA-delete/versioning, public snapshots/AMIs.
- Kubernetes/Helm:
privileged: true,hostNetwork/hostPID, nosecurityContext/runAsNonRoot, wide RBAC (cluster-admin), secrets as env/plaintext,latestimages, no network policies. - Ansible:
shell/commandwith unquoted vars,no_logmissing on secret tasks, world-readable file modes,validate_certs: no.
Method
- Run
checkov/tfsec/kicsfor a broad first pass; they cover hundreds of provider rules. rg '0.0.0.0/0|public|Action.*\*|password|secret|privileged: true'and review each hit's context.- Trace module inputs/variables — an insecure default in a reused module multiplies everywhere.
- Check state handling (remote, encrypted, access-controlled) and CI that applies it (
code-review-cicd).
Gotchas
- A finding's severity depends on blast radius — a public dev sandbox ≠ a public prod data store.
- Scanners miss cross-resource logic (an SG that's fine until paired with a public subnet) — reason about the whole graph.
- Secrets belong in a manager (Vault/SSM/KMS), never in variables or state — flag any inline secret.
References
CIS Benchmarks (AWS/Azure/GCP/Kubernetes); Checkov/tfsec/KICS rule sets; provider well-architected security pillars.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-iac- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infradt-obs-kubernetes
Skill · dynatrace
The pick for Kubernetesazure-kubernetes-automatic-readiness
Skill · microsoft
The pick for Kubernetessecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secrets