What problem does it solve?
Misconfigured Terraform or OpenTofu infrastructure-as-code introduces critical security vulnerabilities, compliance gaps, and operational drift that can cause costly production outages or data breaches before deployment.
Core Features & Use Cases
- Comprehensive IaC Validation: Scans Terraform and OpenTofu configurations for syntax errors, security vulnerabilities, and compliance with 2026 infrastructure best practices.
- Cross-Cloud Risk Detection: Flags critical issues including public storage buckets, overly permissive IAM policies, hardcoded secrets, unencrypted resources, and missing plan-review gates across AWS, GCP, Azure, Cloudflare, Kubernetes, and Vercel.
- Use Case: A DevOps team integrating this skill into their CI pipeline can automatically block PRs with high-risk Terraform misconfigurations, preventing public data exposure and unplanned infrastructure drift before code reaches production.
Quick Start
Use the terraform-validator skill to scan your infrastructure-as-code directory for security risks and configuration violations.