Agent skill

Config Scan

by jwynia in jwynia/agent-skills

Detect security misconfigurations in config files, Docker, and IaC.

MITAuto-check: notesDevOps & Cloud

Install Config Scan

skills CLI
$ npx skills add jwynia/agent-skills --skill config-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jwynia/agent-skills config-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tech/security/config-scan .claude/skills/config-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
config-scan
GitHub stars
170
Token cost
~2k tokens
SKILL.md length
388 words
Files
1
Skills in repo
111
Repo updated
First seen
Licence
MIT

At a glance

Detect security misconfigurations in config files, Docker, and IaC.

  • Reviewing configuration security for containers
  • SKILL.md covers Quick Start, What This Skill Detects, Scan Categories and Output Format, plus 5 more sections
  • Calls git
  • Application settings

What it does

Config Scan is an agent skill from jwynia/agent-skills. Detect security misconfigurations in config files, Docker, and IaC. Use when reviewing configuration security for containers, Kubernetes, Terraform, or application settings.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code, Containers and Container orchestration. It works with Docker, Terraform and Kubernetes. The licence is MIT.

When your agent uses it

  • Reviewing configuration security for containers
  • Application settings

Example prompts

  • “/config-scan”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit e02ec7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Config Scan loads about 2k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 388 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:30
    - Secrets in `.env` files
  • NoteMentions a .env fileSKILL.md:61
    **Files scanned**: `.env`, `.env.*`, `*.env`
  • NoteMentions a .env fileSKILL.md:65
    | Secrets in .env | HIGH | Credentials should use secrets manager |
  • NoteMentions a .env fileSKILL.md:66
    | .env committed | CRITICAL | Should be in .gitignore |
  • NoteMentions a .env fileSKILL.md:72
    # Committed .env files

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jwynia/agent-skills at commit e02ec7e, republished under its MIT licence (© jwynia). 388 words, ~2,045 tokens.

Download SKILL.mdSave it as .claude/skills/config-scan/SKILL.md (or your agent's skills folder).
name
config-scan
description
Detect security misconfigurations in config files, Docker, and IaC. Use when reviewing configuration security for containers, Kubernetes, Terraform, or application settings.
license
MIT
metadata.author
jwynia
metadata.version
1.0
metadata.type
utility
metadata.mode
evaluative
metadata.domain
development

Config Scan

Security review of configuration files and infrastructure as code.

Quick Start

/config-scan                      # Scan all config files
/config-scan --docker             # Docker files only
/config-scan --k8s                # Kubernetes manifests
/config-scan --terraform          # Terraform files
/config-scan --env                # Environment files

What This Skill Detects

Environment Files
  • Secrets in .env files
  • Insecure default values
  • Missing required security variables
Docker Security
  • Running as root
  • Exposed sensitive ports
  • Insecure base images
  • Missing security options
Kubernetes Security
  • Privileged containers
  • Missing resource limits
  • Insecure service accounts
  • Network policy gaps
Infrastructure as Code
  • Overly permissive IAM policies
  • Public S3 buckets
  • Unencrypted storage
  • Missing security groups
Application Config
  • Debug mode enabled
  • Verbose error messages
  • Insecure defaults

Scan Categories

Environment Files

Files scanned: .env, .env.*, *.env

IssueSeverityDescription
Secrets in .envHIGHCredentials should use secrets manager
.env committedCRITICALShould be in .gitignore
DEBUG=trueHIGHDebug mode in production config
Weak secretsMEDIUMShort or simple values

Detection patterns:

# Committed .env files
git ls-files | grep -E '\.env$|\.env\.'

# Secrets in env files
(PASSWORD|SECRET|KEY|TOKEN|CREDENTIAL)=.+

# Debug flags
DEBUG=(true|1|yes)
NODE_ENV=development
Docker Security

Files scanned: Dockerfile, docker-compose.yml

IssueSeverityDescription
USER rootHIGHContainer runs as root
COPY secretsCRITICALSecrets copied into image
Latest tagMEDIUMUnpinned base image
Exposed portsLOWWide port exposure
No healthcheckLOWMissing health monitoring

Detection patterns:

dockerfile
# Running as root (no USER directive)
FROM.*\n(?!.*USER)

# Copying secrets
COPY.*\.(pem|key|crt|env)
COPY.*secret
COPY.*password

# Unpinned images
FROM\s+\w+:latest
FROM\s+\w+\s*$

# Dangerous capabilities
--privileged
--cap-add

docker-compose.yml issues:

yaml
# Privileged mode
privileged: true

# All capabilities
cap_add:
  - ALL

# Host network
network_mode: host

# Sensitive mounts
volumes:
  - /:/host
  - /var/run/docker.sock
Kubernetes Security

Files scanned: *.yaml, *.yml (k8s manifests)

IssueSeverityDescription
privileged: trueCRITICALFull host access
runAsRootHIGHContainer runs as root
No resource limitsMEDIUMDoS risk
hostNetworkHIGHPod uses host network
No securityContextMEDIUMMissing security settings

Detection patterns:

yaml
# Privileged containers
securityContext:
  privileged: true

# Running as root
securityContext:
  runAsUser: 0
runAsNonRoot: false

# Host access
hostNetwork: true
hostPID: true
hostIPC: true

# Dangerous volume mounts
volumes:
  - hostPath:
      path: /

# Missing limits
# (absence of resources.limits)

# Wildcard RBAC
rules:
  - apiGroups: ["*"]
    resources: ["*"]
    verbs: ["*"]
Show full SKILL.md (174 more words)Show less
Terraform/IaC

Files scanned: *.tf, *.tfvars

IssueSeverityDescription
Public S3 bucketCRITICALData exposure
* in IAM policyHIGHOverly permissive
No encryptionHIGHData at rest unencrypted
0.0.0.0/0 ingressHIGHOpen to internet
Hardcoded secretsCRITICALCredentials in TF

Detection patterns:

hcl
# Public S3
acl = "public-read"
acl = "public-read-write"

# Overly permissive IAM
"Action": "*"
"Resource": "*"
"Principal": "*"

# Open security groups
cidr_blocks = ["0.0.0.0/0"]
ingress {
  from_port = 0
  to_port   = 65535

# Missing encryption
encrypted = false
# (or absence of encryption settings)

# Hardcoded secrets
password = "..."
secret_key = "..."
Application Config

Files scanned: config/*.json, *.config.js, application.yml

IssueSeverityDescription
DEBUG=trueHIGHDebug in production
Verbose errorsMEDIUMStack traces exposed
CORS *HIGHAll origins allowed
No HTTPSMEDIUMUnencrypted transport

Detection patterns:

javascript
// Debug mode
debug: true,
DEBUG: true,
NODE_ENV: 'development'

// Verbose errors
showStackTrace: true
detailedErrors: true

// CORS
origin: '*'
origin: true
Access-Control-Allow-Origin: *

// Session security
secure: false  // cookies
httpOnly: false
sameSite: 'none'

Output Format

CONFIG SCAN RESULTS
===================

Files scanned: 23
Issues found: 15

CRITICAL (2)
------------
[!] Dockerfile:1 - Running as root
    No USER directive found
    Fix: Add "USER node" or similar non-root user

[!] terraform/s3.tf:12 - Public S3 bucket
    acl = "public-read"
    Fix: Remove public ACL, use bucket policies

HIGH (5)
--------
[H] docker-compose.yml:15 - Privileged container
    privileged: true
    Fix: Remove privileged flag, use specific capabilities

[H] k8s/deployment.yaml:34 - Missing resource limits
    No CPU/memory limits defined
    Fix: Add resources.limits section

...

MEDIUM (8)
----------
...

Configuration

Ignore Rules

Create .config-scan-ignore:

yaml
# Ignore specific files
files:
  - "docker-compose.dev.yml"
  - "terraform/modules/test/**"

# Ignore specific rules
rules:
  - id: "docker-root-user"
    files: ["Dockerfile.dev"]
    reason: "Development only"

  - id: "k8s-no-limits"
    reason: "Handled by LimitRange"
Scan Profiles
yaml
# .config-scan.yaml
profile: production  # or: development, strict

# Custom thresholds
thresholds:
  fail_on: high
  warn_on: medium

# Specific scanners
scanners:
  docker: true
  kubernetes: true
  terraform: true
  env_files: true
  app_config: true

Best Practices Checked

Docker
  • Non-root user specified
  • Base image pinned to digest
  • No secrets in build
  • Multi-stage build used
  • Health check defined
  • Read-only root filesystem
Kubernetes
  • Non-root security context
  • Resource limits defined
  • Network policies in place
  • No privileged containers
  • Service accounts scoped
  • Secrets encrypted at rest
Terraform
  • State file encrypted
  • No hardcoded secrets
  • Least privilege IAM
  • Encryption enabled
  • Logging enabled
  • No public access by default

Remediation Examples

Docker: Run as Non-Root
dockerfile
# Before
FROM node:18

# After
FROM node:18
RUN groupadd -r app && useradd -r -g app app
USER app
Kubernetes: Security Context
yaml
# Before
containers:
  - name: app
    image: myapp

# After
containers:
  - name: app
    image: myapp
    securityContext:
      runAsNonRoot: true
      runAsUser: 1000
      readOnlyRootFilesystem: true
      allowPrivilegeEscalation: false
Terraform: Private S3
hcl
# Before
resource "aws_s3_bucket" "data" {
  acl = "public-read"
}

# After
resource "aws_s3_bucket" "data" {
  # No ACL (private by default)
}

resource "aws_s3_bucket_public_access_block" "data" {
  bucket = aws_s3_bucket.data.id
  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}

CI/CD Integration

yaml
# GitHub Actions
- name: Config Security Scan
  run: |
    /config-scan --fail-on high

- name: Docker Scan
  run: |
    /config-scan --docker --fail-on critical
  • /security-scan - Full security analysis
  • /secrets-scan - Credential detection
  • /dependency-scan - Package vulnerabilities

© jwynia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tech/security/config-scan of jwynia/agent-skills.

Open the folder on GitHubat commit e02ec7e

Compare with similar skills

Config Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Config Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Config Scan this skilljwynia/agent-skills170—~2kAutomated safety check: NotesMIT
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0
Security Analyzeraiskillstore/marketplace433—~1.2kAutomated safety check: NotesNone
Supercheck Infrastructure Deploymentsupercheck-io/supercheck215—~1.4kAutomated safety check: NotesAGPL-3.0
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit292—~2.7kAutomated safety check: PassMIT

Similar skills

  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    433 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Supercheck Infrastructure Deployment

    supercheck-io/supercheck

    Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

    215 GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    292 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Discover Infra

    rand/cc-polymath

    Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC

    181 GitHub stars~783 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from jwynia/agent-skills

All 111 skills in this repo
  • Devcontainer

    jwynia/agent-skills

    Diagnose devcontainer configuration problems and guide development environment setup.

    170 GitHub stars~1.2k tokensUpdated 7 mo ago
    Auto-check: notes
  • Frontend Design

    jwynia/agent-skills

    Create distinctive, production-grade frontend interfaces with high design quality.

    170 GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Gitea Workflow

    jwynia/agent-skills

    Orchestrate agile development workflows for Gitea repositories using the tea CLI.

    170 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Godot Asset Generator

    jwynia/agent-skills

    Generate game assets using AI image generation APIs (DALL-E, Replicate, fal.ai) and prepare them for Godot.

    170 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Mastra Hono

    jwynia/agent-skills

    Develop AI agents, tools, and workflows with Mastra v1 Beta and Hono servers.

    170 GitHub stars~2.9k tokensUpdated 7 mo ago
    Auto-check passed
  • PPTX Generator

    jwynia/agent-skills

    Create and manipulate PowerPoint PPTX files programmatically.

    170 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Config Scan

What does Config Scan do?

Detect security misconfigurations in config files, Docker, and IaC. Config Scan is an agent skill from jwynia/agent-skills. Detect security misconfigurations in config files, Docker, and IaC.

When should I use Config Scan?

Config Scan fits situations like: reviewing configuration security for containers; application settings.

How do I install Config Scan in Claude Code?

Run `npx skills add jwynia/agent-skills --skill config-scan -a claude-code`. Or copy the skill folder (skills/tech/security/config-scan in jwynia/agent-skills) into .claude/skills/config-scan in your project. Claude Code loads it when a task matches its description.

How do I install Config Scan in Codex?

Run `npx skills add jwynia/agent-skills --skill config-scan -a codex`. Or copy the skill folder (skills/tech/security/config-scan in jwynia/agent-skills) into .agents/skills/config-scan in your project. Codex loads it when a task matches its description.

Can I use Config Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jwynia/agent-skills --skill config-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/config-scan, .gemini/skills/config-scan, .github/skills/config-scan and .opencode/skills/config-scan in your project.

What does Config Scan need to run?

Going by SKILL.md and its folder, Config Scan needs the command-line tools its instructions call (git). Our summary lists: Docker.

Does Config Scan access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Config Scan safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Config Scan use?

Config Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Config Scan use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Config Scan?

Skills that share tags, products or a category with Config Scan: Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars), Security Analyzer (aiskillstore/marketplace, 433 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars) and Devops Excellence (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Config Scan?

jwynia (a GitHub user) maintains it in jwynia/agent-skills, which has 170 GitHub stars. The repository holds 111 skills in this directory. The repository was last updated on February 24, 2026.

Source: jwynia/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.