terraform-security-audit

Automate Terraform security audits for IAM, networking, encryption, secrets, and compliance gaps.

96|9|Updated Mar 21, 2026
One-click install
npx skills add https://github.com/c0x12c/ai-toolkit --skill terraform-security-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: terraform-security-audit
Source: https://github.com/c0x12c/ai-toolkit/tree/main/.codex/skills/terraform-security-audit
Command: npx skills add https://github.com/c0x12c/ai-toolkit --skill terraform-security-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Terraform security reviews are error-prone and time-consuming; teams need a repeatable, automated check that covers IAM, networking, encryption, secrets, access, and compliance.

Core Features & Use Cases

  • Automated security checks across Terraform modules and state
  • Per-area pass/fail reporting with remediation guidance
  • Use before prod deploys, periodic infrastructure reviews, or post-incident hardening

Quick Start

Run the Terraform security audit across your codebase to produce a structured report.

Frequently Asked Questions about terraform-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a Terraform security audit across multiple environments?

Automate a Terraform security audit by running a comprehensive check across your codebase to identify IAM, networking, encryption, secrets, access, and compliance gaps, producing a structured pass or fail report with remediation guidance for each area.

What Terraform IAM and encryption checks should I run before a production deploy?

Before a production deploy, run Terraform security checks that enforce least privilege IAM, verify private subnets, confirm encryption at rest, validate secret handling, and ensure proper tagging and backup configurations to deliver a comprehensive remediation plan.

Does this Terraform security audit work for post-incident infrastructure hardening?

Yes, this Terraform security audit applies to post-incident hardening checks by scanning infrastructure as code to identify access gaps, compliance violations, and encryption misconfigurations, then generating structured remediation steps to secure the affected environments.

How do I check my Terraform codebase for secrets and compliance gaps?

Check your Terraform codebase for secrets and compliance gaps by running an automated security audit that evaluates modules and state, enforcing checks for least privilege IAM, private subnets, encryption, and secret handling to deliver actionable remediation guidance.

What is the best way to review Terraform modules for networking and access security gaps?

The best way to review Terraform modules for networking and access security gaps is to run an automated audit that evaluates private subnets, access controls, and encryption configurations, providing per-area pass or fail reporting with specific remediation guidance.

Can I use this audit for periodic Terraform infrastructure reviews without manual checks?

Yes, you can use this automated audit for periodic infrastructure reviews to replace manual checks, scanning Terraform modules and state across environments to consistently identify IAM, networking, encryption, secrets, access, and compliance gaps with structured reporting.