All skills
hardw00t avatar

/iac-security

@f9bb3b2

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/iac-security

This session only. Nothing lands on disk.

referencesarm_bicep.md

≈654 tokens on demand. Your agent reads this file only when SKILL.md points to it.

ARM / Bicep Security Reference

Azure Resource Manager templates (JSON) and Bicep (DSL that compiles to ARM).

Scanners

Checkov for ARM

# Single template
checkov -f azuredeploy.json --framework arm

# Directory
checkov -d ./arm-templates --framework arm

Checkov for Bicep

# Bicep support requires the bicep CLI on PATH
checkov -d ./bicep --framework bicep

For Bicep, Checkov transpiles to ARM under the hood; errors usually mean bicep isn't installed or the file has unresolved module refs.

KICS for ARM

docker run -v "$(pwd)":/path checkmarx/kics scan \
  -p /path \
  -t AzureResourceManager \
  -o /path

PSRule for Azure

# In CI
Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser
Invoke-PSRule -InputPath './templates/' -Module PSRule.Rules.Azure

PSRule is the Microsoft-first-party option; rule IDs map directly to Azure Security Benchmark.

Bicep-native linter

bicep build main.bicep   # Emits warnings for deprecated / insecure patterns
bicep lint  main.bicep

Security Checklist

Storage

  • supportsHttpsTrafficOnly: true on storage accounts
  • allowBlobPublicAccess: false
  • minimumTlsVersion: TLS1_2
  • networkAcls.defaultAction: Deny with explicit allowlist
  • Encryption at rest enabled (default) + CMK where required

Compute

  • VMs use managed disks (no unmanaged page blobs)
  • OS / data disk encryption enabled (encryptionSettings)
  • No public IP where unnecessary
  • Update management configured
  • osProfile.linuxConfiguration.disablePasswordAuthentication: true (SSH keys only)

Network

  • NSG rules restrictive — no sourceAddressPrefix: "*" on admin ports
  • Azure Firewall / WAF where needed
  • Private endpoints for PaaS (Storage, Key Vault, SQL)
  • publicNetworkAccess: Disabled where supported

Identity

  • Managed Identity preferred over service principals with secrets
  • No hardcoded credentials in parameters / variables
  • Key Vault references for secrets (@Microsoft.KeyVault(...))
  • RBAC role assignments scoped to resource / resource group (not subscription)

Logging

  • Diagnostic settings enabled with Log Analytics / Storage destinations
  • Activity Log export configured
  • Azure Policy diagnostic settings compliance

Inline Suppressions (ARM JSON)

{
  "type": "Microsoft.Storage/storageAccounts",
  "metadata": {
    "checkov": {
      "skip": [
        { "id": "CKV_AZURE_33", "comment": "Queue logs handled centrally" }
      ]
    }
  }
}

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a robust and well-structured routing mechanism for Infrastructure-as-Code (IaC) security tools. It includes low-severity findings related to a demonstration credential inside an intentional test fixture file, the usage of a remote external Kubernetes testing API, and potential indirect prompt injection vectors from unvalidated repository configuration files.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/iac-security