Agent skill

Infra As Code Review

by mohitagw15856 in mohitagw15856/pm-claude-skills

Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code.

MITAuto-check passedDevOps & Cloud

Install Infra As Code Review

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill infra-as-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills infra-as-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/infra-as-code-review .claude/skills/infra-as-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infra-as-code-review
GitHub stars
1.4k
Token cost
~3.3k tokens
SKILL.md length
1,515 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code.

  • Works in 12 steps: IAM and Access Control → Secrets Management → Encryption at Rest → …
  • Asked to review IaC code
  • SKILL.md covers Required Inputs, Output Format, Executive Summary and Findings, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infra As Code Review is an agent skill from mohitagw15856/pm-claude-skills. Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code. Use when asked to review IaC code, audit infrastructure configurations, check cloud security posture, or produce a reusable IaC review checklist. Produces a structured review report with severity-categorized findings, remediation guidance, and a reusable checklist.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Ansible, AWS CloudFormation, Pulumi and Terraform. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to review IaC code
  • Audit infrastructure configurations
  • Check cloud security posture
  • Produce a reusable IaC review checklist

Example prompts

  • “/infra-as-code-review”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. IAM and Access Control
  2. Secrets Management
  3. Encryption at Rest
  4. Encryption in Transit
  5. Network and Public Access
  6. Logging, Monitoring, and Audit
  7. Naming and Tagging Standards
  8. State Management and Backend
  9. Module and Resource Structure
  10. Environment Parity
  11. Cost Impact
  12. Drift Risk

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infra As Code Review loads about 3.3k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 1,515 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 1,515 words, ~3,321 tokens.

Download SKILL.mdSave it as .claude/skills/infra-as-code-review/SKILL.md (or your agent's skills folder).
name
infra-as-code-review
description
Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code. Use when asked to review IaC code, audit infrastructure configurations, check cloud security posture, or produce a reusable IaC review checklist. Produces a structured review report with severity-categorized findings, remediation guidance, and a reusable checklist.

Infrastructure-as-Code Review

Produce a structured infrastructure-as-code review that applies security, reliability, and operational quality standards to a specific body of IaC code. The output serves two purposes: an actionable review report for the code at hand (with findings by severity and specific remediation steps), and a reusable checklist the team can apply to every future IaC change. If the user provides actual code, analyze it and populate the findings table with real issues. If no code is provided, produce the checklist and a template findings report.

Not quite this? Use code-review-guide when the change is application code rather than infrastructure.

Required Inputs

Ask for these if not already provided:

  • IaC tool — Terraform, CloudFormation, Pulumi, Ansible, or CDK
  • Cloud provider — AWS, GCP, Azure, or multi-cloud
  • What the code provisions — a brief description (e.g., "VPC, EKS cluster, and RDS instance for the payments service")
  • Security policies or naming standards in use — any existing org standards to check against; if none, use sensible defaults
  • The IaC code itself — paste or describe it; if not provided, produce the checklist template only and note findings require code

Output Format


IaC Review Report: [What Is Being Provisioned]

Reviewer: [Name / Claude] IaC Tool: [Terraform / CloudFormation / Pulumi / Ansible / CDK] Cloud Provider: [AWS / GCP / Azure] Code Location: [Repo path or PR link] Review Date: [Date] Overall Risk: [Critical / High / Medium / Low]


Executive Summary

SeverityFinding CountResolved in This ReviewCarry-Over Risk
Critical[n][n][Yes/No — explain]
High[n][n][Yes/No — explain]
Medium[n][n][Yes/No — explain]
Low[n][n][Yes/No — explain]
Total[n][n]

Recommendation: [Approve / Approve with Required Changes / Block — one sentence rationale]


Findings

Critical Findings
CRIT-01: [Finding Title]
FieldDetail
SeverityCritical
Category[IAM / Secrets / Encryption / Network / State / Naming / Cost]
Resource[resource_type.resource_name]
File / Line[path/to/file.tf:42]
Risk[What can go wrong — be specific about the attack vector or failure mode]

Current code:

hcl
# [paste the problematic snippet]
resource "aws_s3_bucket" "data" {
  bucket = "my-bucket"
  acl    = "public-read"   # PROBLEM: public read access
}

Remediation:

hcl
resource "aws_s3_bucket" "data" {
  bucket = "my-bucket"
}

resource "aws_s3_bucket_public_access_block" "data" {
  bucket                  = aws_s3_bucket.data.id
  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}

Why this matters: [One sentence linking the specific risk to business impact — data exposure, compliance violation, etc.]


CRIT-02: [Next Critical Finding — repeat structure]

High Findings
HIGH-01: [Finding Title]
FieldDetail
SeverityHigh
Category[Category]
Resource[resource_type.resource_name]
File / Line[path/to/file.tf:line]
Risk[Specific risk description]

Current code:

hcl
# [problematic snippet]

Remediation:

hcl
# [fixed snippet]

Medium Findings
MED-01: [Finding Title]
FieldDetail
SeverityMedium
Category[Category]
Resource[resource_type.resource_name]
File / Line[path/to/file.tf:line]
Risk[Specific risk description]

Remediation: [Prose or code snippet — choose whichever is clearer for this finding]


Low Findings
LOW-01: [Finding Title]
FieldDetail
SeverityLow
Category[Category]
Resource[resource_type.resource_name]
File / Line[path/to/file.tf:line]
Suggestion[What to improve and why]

Reusable IaC Review Checklist

Use this checklist on every IaC pull request. Check every item; mark N/A only when the item genuinely does not apply to the resources being provisioned.

1. IAM and Access Control
  • No wildcard actions ("*") in IAM policies — policies follow least-privilege
  • No wildcard resource ("*") in IAM policies unless explicitly justified with a comment
  • IAM roles use condition keys to restrict scope (e.g., aws:RequestedRegion, sts:ExternalId)
  • No IAM access keys or credentials hardcoded or in plaintext variables
  • EC2 / compute instances use instance profiles, not hardcoded credentials
  • S3 bucket policies do not allow public access unless the bucket is explicitly a public asset bucket
  • Cross-account trust policies name specific account IDs, not "*"
  • Service accounts (GCP) / managed identities (Azure) follow naming conventions and have documented purpose
2. Secrets Management
  • No secrets, passwords, tokens, or API keys in plaintext in any .tf, .yaml, or .json file
  • No secrets in variable default values
  • Secrets sourced from Secrets Manager / Parameter Store / Vault — not from environment variables passed at plan time
  • sensitive = true is set on all output values and variables that contain secrets (Terraform)
  • State backend is encrypted — no unencrypted state files contain sensitive data
  • .gitignore or equivalent excludes *.tfvars, terraform.tfstate, and any file that may contain resolved secrets
3. Encryption at Rest
  • Storage resources (S3, EBS, RDS, DynamoDB, GCS, Azure Blob) have encryption at rest enabled
  • Customer-managed keys (CMK/KMS) are used where required by policy — not solely AWS/GCP/Azure managed keys
  • KMS key rotation is enabled for all CMKs
  • Database snapshots have encryption enabled
  • Encryption is not disabled via encrypted = false or equivalent
4. Encryption in Transit
  • Load balancers terminate TLS — HTTP-only listeners redirect to HTTPS or are absent
  • Minimum TLS version is 1.2; TLS 1.0 and 1.1 are explicitly disabled
  • RDS / database connections require SSL (require_ssl = true or equivalent parameter)
  • Internal service-to-service calls use TLS where the network is not fully private
  • S3 bucket policies include a Deny on non-TLS requests (aws:SecureTransport: false)
5. Network and Public Access
  • Security groups / firewall rules do not permit 0.0.0.0/0 ingress except on ports 80/443 for public-facing services
  • SSH (port 22) and RDP (port 3389) are not open to 0.0.0.0/0
  • Databases are in private subnets — not directly internet-routable
  • publicly_accessible = false on RDS instances unless explicitly required and documented
  • VPC has flow logs enabled
  • Network ACLs and security groups are layered (defense in depth)
  • S3 bucket public access block is enabled at the account and bucket level
6. Logging, Monitoring, and Audit
  • CloudTrail / Cloud Audit Logs / Azure Monitor is enabled across all regions
  • S3 access logging is enabled on buckets containing sensitive or regulated data
  • RDS enhanced monitoring or equivalent is enabled
  • CloudWatch alarms or equivalent are defined for critical metrics (CPU, disk, error rate)
  • Log retention periods are defined — logs not retained indefinitely or deleted within 7 days
7. Naming and Tagging Standards
  • All resources follow the team's naming convention: [env]-[team]-[resource-type]-[identifier]
  • Required tags are present on all taggable resources:
    • Environment (e.g., prod / staging / dev)
    • Team or Owner
    • Service or Application
    • CostCenter (if required by finance policy)
    • ManagedBy: terraform (or equivalent IaC tool tag)
  • No resources with default names (e.g., default-vpc, launch-wizard-1)
Show full SKILL.md (595 more words)Show less
8. State Management and Backend
  • Remote state backend is configured — no local state in repository
  • State backend uses locking (DynamoDB for S3 backend, etc.)
  • State backend bucket/storage has versioning enabled
  • State backend bucket/storage has access logging enabled
  • Workspaces or separate state files are used per environment — no shared state between prod and non-prod
  • terraform.tfstate and *.tfstate.backup are in .gitignore
9. Module and Resource Structure
  • Modules are versioned with explicit version pins — no floating source = "git::...?ref=main"
  • Provider versions are pinned in required_providers — no unconstrained >= x.y
  • Terraform version is pinned in required_version
  • Modules have a clear single responsibility — not one module that provisions everything
  • No copy-paste duplication — repeated patterns use modules or loops (for_each, count)
  • Outputs expose only what downstream consumers need — no unnecessary output sprawl
10. Environment Parity
  • Prod and non-prod environments use the same module code, parameterized by environment variable
  • Instance sizes and replica counts differ by environment via variables — not by separate code branches
  • Non-prod does not have security controls disabled "to save money" (encryption off, logging off)
11. Cost Impact
  • Large instance types (e.g., r5.16xlarge) or storage allocations are justified in a comment
  • Data transfer costs are considered for cross-region or cross-AZ architectures
  • Reserved instance or committed use discount eligibility is noted for long-lived resources
  • Auto-scaling is configured for variable workloads — no fixed oversized fleets for spiky traffic
  • Lifecycle policies are set on S3 buckets storing time-bounded data (logs, backups)
12. Drift Risk
  • No resources that are commonly mutated in the console are managed by IaC without import documentation
  • lifecycle { prevent_destroy = true } is set on stateful resources in production (databases, state buckets)
  • ignore_changes is used sparingly and each instance is documented with a rationale comment
  • A plan is run against the live environment as part of the PR process — no unreviewed drift

Findings Summary Table

IDTitleSeverityCategoryFileStatus
CRIT-01[Title]Critical[Category][file:line]Open
HIGH-01[Title]High[Category][file:line]Open
MED-01[Title]Medium[Category][file:line]Open
LOW-01[Title]Low[Category][file:line]Open

Required Actions Before Merge

List only Critical and High findings that must be resolved before this code is merged:

  1. CRIT-01 [Title] — [One-line remediation instruction]
  2. HIGH-01 [Title] — [One-line remediation instruction]

Medium and Low findings should be tracked as follow-up issues with a committed resolution date.


Review conducted by [Reviewer] on [Date] — checklist version [1.0]


Quality Checks

  • Every finding includes: severity, category, specific resource name, file and line number, current code, and fixed code
  • Checklist covers all 12 categories: IAM, Secrets, Encryption at Rest, Encryption in Transit, Network, Logging, Naming/Tagging, State, Module Structure, Environment Parity, Cost, and Drift
  • Executive summary table is filled with real counts — not all zeros or all placeholders
  • "Required Actions Before Merge" section lists only Critical and High items
  • Code snippets in findings show both the problematic code AND the corrected version
  • Overall risk rating is justified by the highest-severity open finding
  • Checklist items are binary (checkable) — not narrative observations

Anti-Patterns

  • Do not mark a finding as Low if it involves hardcoded credentials or secrets in any form — always Critical
  • Do not review IaC in isolation from the deployment context — networking and IAM must be evaluated together
  • Do not produce narrative findings without the specific resource name, file, and line number
  • Do not skip the "Required Actions Before Merge" summary — reviewers need a clear blocking list, not just a full report
  • Do not approve code where encryption at rest or in transit is missing on data stores, even if not explicitly flagged by the requester

Example Trigger Phrases

  • "Review IaC code."
  • "Audit infrastructure configurations."
  • "Check cloud security posture."
  • "Produce a reusable IaC review checklist."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/infra-as-code-review of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Infra As Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infra As Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infra As Code Review this skillmohitagw15856/pm-claude-skills1.4k—~3.3kAutomated safety check: PassMIT
Audit Infrastructure As Codecyberful/cyberful135—~649Automated safety check: PassAGPL-3.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT
Detecting Infrastructure Driftjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Generating Infrastructure As Codejeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
Infra As CodeLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassMIT

Similar skills

  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Detecting Infrastructure Drift

    jeremylongshore/tons-of-skills-marketplace

    Execute use when detecting infrastructure drift from desired state.

    2.8k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Generating Infrastructure As Code

    jeremylongshore/tons-of-skills-marketplace

    Execute use when generating infrastructure as code configurations.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Infra As Code

    LeoYeAI/openclaw-master-skills

    Define and manage cloud infrastructure with code. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Infrastructure As Code

    seb1n/awesome-ai-agent-skills

    Define, deploy, and manage cloud infrastructure as code using tools like Terraform, Pulumi, CloudFormation, and CDK, ensuring consistency, repeatability, and version control.

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Infra As Code Review

What does Infra As Code Review do?

Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code. Infra As Code Review is an agent skill from mohitagw15856/pm-claude-skills. Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code.

When should I use Infra As Code Review?

Infra As Code Review fits situations like: asked to review IaC code; audit infrastructure configurations; check cloud security posture; produce a reusable IaC review checklist.

How do I install Infra As Code Review in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill infra-as-code-review -a claude-code`. Or copy the skill folder (skills/infra-as-code-review in mohitagw15856/pm-claude-skills) into .claude/skills/infra-as-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Infra As Code Review in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill infra-as-code-review -a codex`. Or copy the skill folder (skills/infra-as-code-review in mohitagw15856/pm-claude-skills) into .agents/skills/infra-as-code-review in your project. Codex loads it when a task matches its description.

Can I use Infra As Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill infra-as-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infra-as-code-review, .gemini/skills/infra-as-code-review, .github/skills/infra-as-code-review and .opencode/skills/infra-as-code-review in your project.

What does Infra As Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Infra As Code Review is instructions for the agent only.

Does Infra As Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infra As Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Infra As Code Review use?

Infra As Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infra As Code Review use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infra As Code Review?

Skills that share tags, products or a category with Infra As Code Review: Audit Infrastructure As Code (cyberful/cyberful, 135 stars), AWS Sst Development (zxkane/aws-skills, 367 stars), Detecting Infrastructure Drift (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Generating Infrastructure As Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infra As Code Review?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.