Agent skill · Security

iac-security-scanner

Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi

a5c-aigithub.com/a5c-aiGitHub ↗
claude-codecodexcan modify filesMIT
Install
npx skills add a5c-ai/babysitter --skill iac-security-scanner --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 2
SKILL.md size: 5 KB
Bundled scripts: none
Allowed tools: -Bash-Read-Write-Glob-Grep-WebFetch
Path: library/specializations/security-compliance/skills/iac-security-scanner/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 1,642
Language: JavaScript

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# IaC Security Scanner Skill ## Purpose Infrastructure as Code security scanning and policy enforcement to identify misconfigurations, security vulnerabilities, and compliance violations in cloud infrastructure definitions before deployment. ## Capabilities ### Terraform Security Scanning - Scan Terraform configurations for security misconfigurations - Check for exposed resources (public S3 buckets, open security groups) - Validate encryption settings for data at rest and in transit - Detect hardcoded secrets in Terraform files - Analyze Terraform state files for sensitive data exposure ### CloudFormation Analysis - Scan CloudFormation templates for security issues - Check IAM policy configurations for least privilege - Validate network configuration security - Detect insecure default configurations ### Kubernetes Manifest Scanning - Analyze Kubernetes YAML manifests for security issues - Check pod security standards compliance - Validate resource limits and quotas - Detect privileged containers and host path mounts ### Pulumi Code Analysis - Scan Pulumi TypeScript/Python code for security issues - Check cloud resource configurations - Validate security best practices ### Policy En

What's inside
Steps it walks through
  1. Purpose
  2. Capabilities
  3. Terraform Security Scanning
  4. CloudFormation Analysis
  5. Kubernetes Manifest Scanning
  6. Pulumi Code Analysis
  7. Policy Enforcement
  8. Compliance Mapping
  9. Integrations
  10. Target Processes
  11. Input Schema
  12. Output Schema
  13. Usage Example
Ships with 1 file
  • README.md
More from babysitter
All skills →
About this skill
What does the iac-security-scanner skill do?

Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi

How do I install it?

Run `npx skills add a5c-ai/babysitter --skill iac-security-scanner --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From a5c-ai/babysitter, a repository with 1,642 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going