forge-audit

Audit IaC and cloud configurations for security, cost, and reliability gaps.

69|8|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/tonone-ai/tonone --skill forge-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forge-audit
Source: https://github.com/tonone-ai/tonone/tree/main/team/forge/skills/forge-audit
Command: npx skills add https://github.com/tonone-ai/tonone --skill forge-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Consistent, automated visibility into infrastructure security, cost waste, and reliability gaps across IaC and cloud configurations.

Core Features & Use Cases

  • Automated detection of misconfigurations, insecure IAM permissions, and exposed resources.
  • Structured audit findings with prioritized fixes and actionable guidance.
  • Reusable steps to reproduce the audit across projects and environments.

Quick Start

Provide an end-to-end infra audit starting from project discovery and deliver a prioritized report.

Frequently Asked Questions about forge-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit cloud infrastructure for security and cost waste?

Auditing cloud infrastructure for security and cost waste involves scanning IaC and cloud configurations to detect misconfigurations, insecure IAM permissions, and exposed resources, which generates a structured report with prioritized remediation steps.

Does infrastructure auditing work with Terraform, Pulumi, and Kubernetes configurations?

Yes, infrastructure auditing works with Terraform, Pulumi, CDK, CloudFormation, Docker, and Kubernetes deployments to surface security, cost, and reliability gaps across diverse cloud environments.

How do I get a prioritized report for IaC misconfigurations?

To get a prioritized report for IaC misconfigurations, audit your infrastructure configurations to surface red, yellow, and blue findings, which include actionable guidance and specific remediation steps.

What is the best way to find insecure IAM permissions in IaC deployments?

The best way to find insecure IAM permissions in IaC deployments is to run an automated infrastructure audit that detects exposed resources and delivers a structured report with actionable remediation guidance.

Can I reproduce infrastructure security audits across multiple cloud projects?

Yes, you can reproduce infrastructure security audits across multiple cloud projects by applying reusable audit steps that consistently evaluate security, reliability, and cost waste in diverse environments.