sc-iac

Detect security misconfigurations in Dockerfiles, Kubernetes manifests, Terraform, and CI/CD workflows.

56|5|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/ersinkoc/security-check --skill sc-iac
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sc-iac
Source: https://github.com/ersinkoc/security-check/tree/main/skills/sc-iac
Command: npx skills add https://github.com/ersinkoc/security-check --skill sc-iac

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill analyzes Infrastructure-as-Code artifacts (Dockerfiles, Kubernetes manifests, Terraform files, and CI workflows) to detect security misconfigurations and weaknesses across the build-to-runtime pipeline.

Core Features & Use Cases

  • Automated IaC security checks across Dockerfiles, Kubernetes manifests, Terraform, and GitHub Actions workflows.
  • Guidance on misconfigurations such as privileged containers, over-permissive IAM, hostPath, insecure network practices, and insecure workflow patterns.
  • Use Case: Integrate into CI/CD to catch issues before deployment and ensure policy compliance.

Quick Start

Run the IaC scan against your repository to identify misconfigurations in Dockerfiles, Kubernetes manifests, Terraform configurations, and GitHub Actions workflows.

Frequently Asked Questions about sc-iac

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan Terraform and Kubernetes manifests for security misconfigurations?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.

What security misconfigurations should I look for in Infrastructure-as-Code?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.

Can I integrate IaC security checks into my CI/CD pipelines?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.

How do I detect privileged containers and over-permissive IAM in Terraform?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.

What is the best way to validate Dockerfiles for insecure defaults like running as root?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.

Does this IaC security scan work with GitHub Actions workflows?

To check Dockerfiles and GitHub Actions workflows for insecure defaults, the IaC scan identifies insecure workflow patterns and Docker misconfigurations such as running as root. It analyzes your CI/CD pipelines to catch exposure risks and privilege escalation before deployment.