All skills
hardw00t avatar

/iac-security

@f9bb3b2

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/iac-security

This session only. Nothing lands on disk.

referencescloudformation.md

≈699 tokens on demand. Your agent reads this file only when SKILL.md points to it.

CloudFormation Security Reference

CloudFormation (YAML / JSON) scanning, lint, and security checklist.

Scanners

Checkov

# Single template
checkov -f template.yaml --framework cloudformation

# Directory
checkov -d ./cfn-templates --framework cloudformation

# With parameters file (resolves !Ref values for more accurate checks)
checkov -f template.yaml --var-file parameters.json

cfn-lint

pip install cfn-lint

# Basic lint
cfn-lint template.yaml

# Include extra rule packs
cfn-lint template.yaml -a /path/to/additional/rules

# Ignore specific rules
cfn-lint template.yaml -i W3002

cfn-lint catches schema / resource-property problems that security scanners miss (bad intrinsic functions, invalid resource types). Run it BEFORE security scans to avoid noise from malformed templates.

cfn-nag

gem install cfn-nag

# Scan
cfn_nag_scan --input-path template.yaml

# JSON output
cfn_nag_scan --input-path template.yaml --output-format json

# Rule suppression via metadata
#   Metadata:
#     cfn_nag:
#       rules_to_suppress:
#         - id: W41
#           reason: "Bucket is public by design"

KICS

docker run -v /path/to/cfn:/path checkmarx/kics scan -p /path -t CloudFormation

docker run -v "$(pwd)":/path checkmarx/kics scan \
  -p /path \
  -t CloudFormation \
  -o /path \
  --report-formats json,sarif

Security Checklist

IAM

  • No inline policies with Action: "*" or Resource: "*"
  • Roles use least privilege
  • ManagedPolicyArns preferred over inline
  • No hardcoded credentials in Parameters or Metadata
  • AssumeRolePolicyDocument scoped to specific principals

Encryption

  • S3 buckets encrypted (BucketEncryption with SSE-S3 or SSE-KMS)
  • RDS StorageEncrypted: true
  • EBS Encrypted: true
  • SQS KmsMasterKeyId set
  • SNS KmsMasterKeyId set
  • Secrets Manager / SSM Parameter Store for secrets (not Parameters with NoEcho)

Network

  • Security groups restrictive (no 0.0.0.0/0 on admin ports)
  • NACLs properly configured
  • VPC endpoints for AWS services (S3, DynamoDB, KMS)
  • No public IPs on internal resources (AssociatePublicIpAddress: false)

Logging & Monitoring

  • CloudTrail enabled (multi-region, log file validation)
  • VPC flow logs configured
  • Access logging on S3 / ALB / CloudFront
  • CloudWatch log retention set (not default infinite)

Inline Suppressions

Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Metadata:
      checkov:
        skip:
          - id: CKV_AWS_18
            comment: "Access logs live in sibling bucket"
      cfn_nag:
        rules_to_suppress:
          - id: W35
            reason: "Access logs live in sibling bucket"

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a robust and well-structured routing mechanism for Infrastructure-as-Code (IaC) security tools. It includes low-severity findings related to a demonstration credential inside an intentional test fixture file, the usage of a remote external Kubernetes testing API, and potential indirect prompt injection vectors from unvalidated repository configuration files.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/iac-security