Agent Bom Scan Infra
LeoYeAI/openclaw-master-skills
Scan infrastructure-as-code, cloud configurations, and find secrets.
Detect security misconfigurations in config files, Docker, and IaC.
$ npx skills add jwynia/agent-skills --skill config-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jwynia/agent-skills config-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tech/security/config-scan .claude/skills/config-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .claude/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jwynia/agent-skills --skill config-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jwynia/agent-skills config-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tech/security/config-scan .agents/skills/config-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .agents/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jwynia/agent-skills --skill config-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jwynia/agent-skills config-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tech/security/config-scan .cursor/skills/config-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .cursor/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jwynia/agent-skills.git --path skills/tech/security/config-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jwynia/agent-skills --skill config-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jwynia/agent-skills config-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tech/security/config-scan .gemini/skills/config-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .gemini/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jwynia/agent-skills config-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jwynia/agent-skills --skill config-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tech/security/config-scan .github/skills/config-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .github/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jwynia/agent-skills --skill config-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jwynia/agent-skills config-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tech/security/config-scan .opencode/skills/config-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "config-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/config-scan into .opencode/skills/config-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "config-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
config-scanDetect security misconfigurations in config files, Docker, and IaC.
Config Scan is an agent skill from jwynia/agent-skills. Detect security misconfigurations in config files, Docker, and IaC. Use when reviewing configuration security for containers, Kubernetes, Terraform, or application settings.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code, Containers and Container orchestration. It works with Docker, Terraform and Kubernetes. The licence is MIT.
Read from SKILL.md and the folder at commit e02ec7e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Config Scan loads about 2k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 388 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Secrets in `.env` files**Files scanned**: `.env`, `.env.*`, `*.env`| Secrets in .env | HIGH | Credentials should use secrets manager || .env committed | CRITICAL | Should be in .gitignore |# Committed .env filesAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jwynia/agent-skills at commit e02ec7e, republished under its MIT licence (© jwynia). 388 words, ~2,045 tokens.
.claude/skills/config-scan/SKILL.md (or your agent's skills folder).Security review of configuration files and infrastructure as code.
/config-scan # Scan all config files
/config-scan --docker # Docker files only
/config-scan --k8s # Kubernetes manifests
/config-scan --terraform # Terraform files
/config-scan --env # Environment files.env filesFiles scanned: .env, .env.*, *.env
| Issue | Severity | Description |
|---|---|---|
| Secrets in .env | HIGH | Credentials should use secrets manager |
| .env committed | CRITICAL | Should be in .gitignore |
| DEBUG=true | HIGH | Debug mode in production config |
| Weak secrets | MEDIUM | Short or simple values |
Detection patterns:
# Committed .env files
git ls-files | grep -E '\.env$|\.env\.'
# Secrets in env files
(PASSWORD|SECRET|KEY|TOKEN|CREDENTIAL)=.+
# Debug flags
DEBUG=(true|1|yes)
NODE_ENV=developmentFiles scanned: Dockerfile, docker-compose.yml
| Issue | Severity | Description |
|---|---|---|
| USER root | HIGH | Container runs as root |
| COPY secrets | CRITICAL | Secrets copied into image |
| Latest tag | MEDIUM | Unpinned base image |
| Exposed ports | LOW | Wide port exposure |
| No healthcheck | LOW | Missing health monitoring |
Detection patterns:
# Running as root (no USER directive)
FROM.*\n(?!.*USER)
# Copying secrets
COPY.*\.(pem|key|crt|env)
COPY.*secret
COPY.*password
# Unpinned images
FROM\s+\w+:latest
FROM\s+\w+\s*$
# Dangerous capabilities
--privileged
--cap-adddocker-compose.yml issues:
# Privileged mode
privileged: true
# All capabilities
cap_add:
- ALL
# Host network
network_mode: host
# Sensitive mounts
volumes:
- /:/host
- /var/run/docker.sockFiles scanned: *.yaml, *.yml (k8s manifests)
| Issue | Severity | Description |
|---|---|---|
| privileged: true | CRITICAL | Full host access |
| runAsRoot | HIGH | Container runs as root |
| No resource limits | MEDIUM | DoS risk |
| hostNetwork | HIGH | Pod uses host network |
| No securityContext | MEDIUM | Missing security settings |
Detection patterns:
# Privileged containers
securityContext:
privileged: true
# Running as root
securityContext:
runAsUser: 0
runAsNonRoot: false
# Host access
hostNetwork: true
hostPID: true
hostIPC: true
# Dangerous volume mounts
volumes:
- hostPath:
path: /
# Missing limits
# (absence of resources.limits)
# Wildcard RBAC
rules:
- apiGroups: ["*"]
resources: ["*"]
verbs: ["*"]Files scanned: *.tf, *.tfvars
| Issue | Severity | Description |
|---|---|---|
| Public S3 bucket | CRITICAL | Data exposure |
| * in IAM policy | HIGH | Overly permissive |
| No encryption | HIGH | Data at rest unencrypted |
| 0.0.0.0/0 ingress | HIGH | Open to internet |
| Hardcoded secrets | CRITICAL | Credentials in TF |
Detection patterns:
# Public S3
acl = "public-read"
acl = "public-read-write"
# Overly permissive IAM
"Action": "*"
"Resource": "*"
"Principal": "*"
# Open security groups
cidr_blocks = ["0.0.0.0/0"]
ingress {
from_port = 0
to_port = 65535
# Missing encryption
encrypted = false
# (or absence of encryption settings)
# Hardcoded secrets
password = "..."
secret_key = "..."Files scanned: config/*.json, *.config.js, application.yml
| Issue | Severity | Description |
|---|---|---|
| DEBUG=true | HIGH | Debug in production |
| Verbose errors | MEDIUM | Stack traces exposed |
| CORS * | HIGH | All origins allowed |
| No HTTPS | MEDIUM | Unencrypted transport |
Detection patterns:
// Debug mode
debug: true,
DEBUG: true,
NODE_ENV: 'development'
// Verbose errors
showStackTrace: true
detailedErrors: true
// CORS
origin: '*'
origin: true
Access-Control-Allow-Origin: *
// Session security
secure: false // cookies
httpOnly: false
sameSite: 'none'CONFIG SCAN RESULTS
===================
Files scanned: 23
Issues found: 15
CRITICAL (2)
------------
[!] Dockerfile:1 - Running as root
No USER directive found
Fix: Add "USER node" or similar non-root user
[!] terraform/s3.tf:12 - Public S3 bucket
acl = "public-read"
Fix: Remove public ACL, use bucket policies
HIGH (5)
--------
[H] docker-compose.yml:15 - Privileged container
privileged: true
Fix: Remove privileged flag, use specific capabilities
[H] k8s/deployment.yaml:34 - Missing resource limits
No CPU/memory limits defined
Fix: Add resources.limits section
...
MEDIUM (8)
----------
...Create .config-scan-ignore:
# Ignore specific files
files:
- "docker-compose.dev.yml"
- "terraform/modules/test/**"
# Ignore specific rules
rules:
- id: "docker-root-user"
files: ["Dockerfile.dev"]
reason: "Development only"
- id: "k8s-no-limits"
reason: "Handled by LimitRange"# .config-scan.yaml
profile: production # or: development, strict
# Custom thresholds
thresholds:
fail_on: high
warn_on: medium
# Specific scanners
scanners:
docker: true
kubernetes: true
terraform: true
env_files: true
app_config: true# Before
FROM node:18
# After
FROM node:18
RUN groupadd -r app && useradd -r -g app app
USER app# Before
containers:
- name: app
image: myapp
# After
containers:
- name: app
image: myapp
securityContext:
runAsNonRoot: true
runAsUser: 1000
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false# Before
resource "aws_s3_bucket" "data" {
acl = "public-read"
}
# After
resource "aws_s3_bucket" "data" {
# No ACL (private by default)
}
resource "aws_s3_bucket_public_access_block" "data" {
bucket = aws_s3_bucket.data.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}# GitHub Actions
- name: Config Security Scan
run: |
/config-scan --fail-on high
- name: Docker Scan
run: |
/config-scan --docker --fail-on critical/security-scan - Full security analysis/secrets-scan - Credential detection/dependency-scan - Package vulnerabilities© jwynia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/tech/security/config-scan of jwynia/agent-skills.
Open the folder on GitHubat commit e02ec7e
Config Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Config Scan this skilljwynia/agent-skills | 170 | — | ~2k | Automated safety check: Notes | MIT | |
| Agent Bom Scan InfraLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Security Analyzeraiskillstore/marketplace | 433 | — | ~1.2k | Automated safety check: Notes | None | |
| Supercheck Infrastructure Deploymentsupercheck-io/supercheck | 215 | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | |
| Devops Excellencemajiayu000/spellbook | 287 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Devops Deploymentyonatangross/orchestkit | 292 | — | ~2.7k | Automated safety check: Pass | MIT |
LeoYeAI/openclaw-master-skills
Scan infrastructure-as-code, cloud configurations, and find secrets.
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
supercheck-io/supercheck
Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
yonatangross/orchestkit
A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.
rand/cc-polymath
Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC
jwynia/agent-skills
Diagnose devcontainer configuration problems and guide development environment setup.
jwynia/agent-skills
Create distinctive, production-grade frontend interfaces with high design quality.
jwynia/agent-skills
Orchestrate agile development workflows for Gitea repositories using the tea CLI.
jwynia/agent-skills
Generate game assets using AI image generation APIs (DALL-E, Replicate, fal.ai) and prepare them for Godot.
jwynia/agent-skills
Develop AI agents, tools, and workflows with Mastra v1 Beta and Hono servers.
jwynia/agent-skills
Create and manipulate PowerPoint PPTX files programmatically.
Works with
Categories
Detect security misconfigurations in config files, Docker, and IaC. Config Scan is an agent skill from jwynia/agent-skills. Detect security misconfigurations in config files, Docker, and IaC.
Config Scan fits situations like: reviewing configuration security for containers; application settings.
Run `npx skills add jwynia/agent-skills --skill config-scan -a claude-code`. Or copy the skill folder (skills/tech/security/config-scan in jwynia/agent-skills) into .claude/skills/config-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jwynia/agent-skills --skill config-scan -a codex`. Or copy the skill folder (skills/tech/security/config-scan in jwynia/agent-skills) into .agents/skills/config-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jwynia/agent-skills --skill config-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/config-scan, .gemini/skills/config-scan, .github/skills/config-scan and .opencode/skills/config-scan in your project.
Going by SKILL.md and its folder, Config Scan needs the command-line tools its instructions call (git). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Config Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Config Scan: Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars), Security Analyzer (aiskillstore/marketplace, 433 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars) and Devops Excellence (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jwynia (a GitHub user) maintains it in jwynia/agent-skills, which has 170 GitHub stars. The repository holds 111 skills in this directory. The repository was last updated on February 24, 2026.
Source: jwynia/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.