What problem does it solve?
This Skill helps developers maintain security best practices in their Terraform and Lambda configurations by providing a comprehensive review of IAM roles, policies, and other security settings.
Core Features & Use Cases
- IAM Role and Policy Review: Checks for common security issues in IAM roles and policies, such as wildcard actions and scoped ARNs.
- Infrastructure Resource Security: Validates S3 bucket public access settings and server-side encryption configurations.
- Lambda Function Security: Inspects Lambda function code for hardcoded secrets and secure logging practices.
- SSM Parameter Store Usage: Ensures secure usage of the AWS Systems Manager Parameter Store.
- Remote State Management: Validates backend configuration for remote state management.
- Use Case: After making changes to Terraform or Lambda configurations, use this Skill to quickly identify and address potential security vulnerabilities before deploying code.
Quick Start
Run the security review after modifying any Terraform or Lambda code with the command /security.