Agent skill

Iac Security Review

by OWASP in OWASP/secure-agent-playbook

Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation).

CC-BY-4.0Auto-check passedDevOps & Cloud

Install Iac Security Review

skills CLI
$ npx skills add OWASP/secure-agent-playbook --skill iac-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OWASP/secure-agent-playbook iac-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/iac-security-review .claude/skills/iac-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iac-security-review
GitHub stars
188
Token cost
~694 tokens
SKILL.md length
236 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation).

  • Works in 4 steps: Detect IaC Type — Identify the… → Systematic Review by Security Domain… → Check Against Benchmarks — Validate… → …
  • Reviewing IaC files for misconfigurations
  • SKILL.md covers Steps, Output and References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Iac Security Review is an agent skill from OWASP/secure-agent-playbook. Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). Use when reviewing IaC files for misconfigurations, overpermissioning, exposed resources, missing encryption, secrets in code, and supply chain risks. Covers CIS benchmarks and cloud security best practices.

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code, Security review and Container orchestration. It works with Kubernetes, Terraform and AWS CloudFormation. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.

When your agent uses it

  • Reviewing IaC files for misconfigurations
  • Overpermissioning
  • Exposed resources
  • Missing encryption

Example prompts

  • “/iac-security-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Detect IaC Type — Identify the infrastructure technology from file extensions and content
  2. Systematic Review by Security Domain (priority order)
  3. Check Against Benchmarks — Validate configurations against
  4. Produce Findings — For each finding: cite resource path, explain the misconfiguration, describe attack scenario, provide fixed code…

What it can do on your machine

Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iac Security Review loads about 694 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 236 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~694

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 236 words, ~694 tokens.

Download SKILL.mdSave it as .claude/skills/iac-security-review/SKILL.md (or your agent's skills folder).
name
iac-security-review
description
Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). Use when reviewing IaC files for misconfigurations, overpermissioning, exposed resources, missing encryption, secrets in code, and supply chain risks. Covers CIS benchmarks and cloud security best practices.
license
CC-BY-4.0

IaC Security Review

Review infrastructure-as-code for security risks by following the full procedure in plays/iac-security-review.md.

Steps

  1. Detect IaC Type — Identify the infrastructure technology from file extensions and content:

    • .tf / .tofu files → Terraform/OpenTofu (reference data/secure-code-prompts/terraform.md)
    • Kubernetes manifests (apiVersion, kind: Deployment/Pod/Service) → Kubernetes (reference data/secure-code-prompts/kubernetes.md)
    • CloudFormation templates (AWSTemplateFormatVersion, Resources with AWS::) → CloudFormation (reference data/secure-code-prompts/cloudformation.md)
    • Helm charts (Chart.yaml, templates/) → Kubernetes review with Helm-specific checks
  2. Systematic Review by Security Domain (priority order):

    • Identity & Access Management — Overly permissive policies, wildcard permissions, hardcoded credentials, privilege escalation paths
    • Secrets Management — Hardcoded secrets, plaintext credentials, missing vault/secret manager integration
    • Network Security — Open ingress (0.0.0.0/0), unrestricted ports, missing segmentation, public exposure
    • Encryption — Missing encryption at rest/in transit, weak algorithms, default keys
    • Storage Security — Public buckets, unencrypted volumes, missing versioning
    • Logging & Monitoring — Missing audit trails, disabled CloudTrail/audit logging
    • Resource Exposure — Databases, admin interfaces, APIs exposed to internet
    • Supply Chain — Unpinned versions, untrusted sources, unverified modules/images
    • Platform-Specific Risks — Terraform state exposure, K8s privileged containers, CFN nested stack integrity
  3. Check Against Benchmarks — Validate configurations against:

    • CIS Benchmarks (AWS/Azure/GCP/Kubernetes)
    • Cloud provider security best practices
    • Pod Security Standards (for Kubernetes)
  4. Produce Findings — For each finding: cite resource path, explain the misconfiguration, describe attack scenario, provide fixed code example, rate severity.

Output

Findings sorted by severity using templates/finding.md format, summary with severity counts, and secure configuration improvements section.

References

  • CIS Benchmarks (AWS, Azure, GCP, Kubernetes)
  • OWASP Infrastructure Security Cheat Sheet
  • NSA/CISA Kubernetes Hardening Guide
  • Cloud provider Well-Architected Frameworks

© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/code-security-skills/skills/iac-security-review of OWASP/secure-agent-playbook.

Open the folder on GitHubat commit 1b5fd4c

Compare with similar skills

Iac Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iac Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iac Security Review this skillOWASP/secure-agent-playbook188—~694Automated safety check: PassCC-BY-4.0
Security Analyzeraiskillstore/marketplace433—~1.2kAutomated safety check: NotesNone
Implementing Infrastructure As Code Security Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Iac Securityhardw00t/ai-security-arsenal105—~2.4kAutomated safety check: PassNone
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    433 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Implementing Infrastructure As Code Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Implements automated security scanning for Infrastructure as Code using Checkov, tfsec, and KICS to detect misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts, plus…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    105 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Advisor

    diegosouzapw/awesome-omni-skills

    AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.3k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed

More from OWASP/secure-agent-playbook

All 14 skills in this repo
  • Prd Securability Enhancement

    OWASP/secure-agent-playbook

    Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.

    188 GitHub stars~4.6k tokensUpdated 14 days ago
    Auto-check passed
  • Securability Engineering Review

    OWASP/secure-agent-playbook

    Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…

    188 GitHub stars~4.6k tokensUpdated 14 days ago
    Auto-check passed
  • Securability Engineering

    OWASP/secure-agent-playbook

    Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…

    188 GitHub stars~5.8k tokensUpdated 14 days ago
    Auto-check passed
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    188 GitHub stars~542 tokensUpdated 14 days ago
    Auto-check passed
  • AI Security Verification

    OWASP/secure-agent-playbook

    Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

    188 GitHub stars~876 tokensUpdated 14 days ago
    Auto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 14 days ago
    Auto-check passed

Questions about Iac Security Review

What does Iac Security Review do?

Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). Iac Security Review is an agent skill from OWASP/secure-agent-playbook. Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation).

When should I use Iac Security Review?

Iac Security Review fits situations like: reviewing IaC files for misconfigurations; overpermissioning; exposed resources; missing encryption.

How do I install Iac Security Review in Claude Code?

Run `npx skills add OWASP/secure-agent-playbook --skill iac-security-review -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/iac-security-review in OWASP/secure-agent-playbook) into .claude/skills/iac-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Iac Security Review in Codex?

Run `npx skills add OWASP/secure-agent-playbook --skill iac-security-review -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/iac-security-review in OWASP/secure-agent-playbook) into .agents/skills/iac-security-review in your project. Codex loads it when a task matches its description.

Can I use Iac Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill iac-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iac-security-review, .gemini/skills/iac-security-review, .github/skills/iac-security-review and .opencode/skills/iac-security-review in your project.

What does Iac Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Iac Security Review is instructions for the agent only.

Does Iac Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Iac Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iac Security Review use?

Iac Security Review is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iac Security Review use?

About 694 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iac Security Review?

Skills that share tags, products or a category with Iac Security Review: Security Analyzer (aiskillstore/marketplace, 433 stars), Implementing Infrastructure As Code Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iac Security (hardw00t/ai-security-arsenal, 105 stars) and Code Security (semgrep/skills, 324 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iac Security Review?

OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 188 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.

Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.