
Terraform Code Review & Security Hardening
Review & harden Terraform configs for security compliance
What You Can Do
You submit Terraform code and Claude automatically audits it for security vulnerabilities, compliance gaps, and hardening opportunities. You get detailed findings mapped to CIS Benchmarks, AWS/Azure/GCP best practices, and actionable remediation steps with code examples.
Features
detects hardcoded secrets, overpermissive IAM policies, and unencrypted resources
flags non-compliant configurations and links to remediation guidance
identifies expensive resource configurations and rightsizing opportunities
checks for encryption, logging, tagging, and multi-region failover readiness
audits role permissions, cross-account access, and least-privilege violations
evaluates remote state backend encryption, access controls, and locking
validates AWS, Azure, GCP, and hybrid infrastructure patterns
generates corrected Terraform blocks with explanations for each change
Example Output
Security Audit Report: vpc.tf
Critical Issues (3)
- ❌ S3 bucket
prod-logshas public ACL (Line 42)- Remediation: Add
acl = "private"andblock_public_acls = true
- Remediation: Add
- ❌ RDS instance uses
publicly_accessible = true(Line 18)- Remediation: Set to
falseand use security group for access control
- Remediation: Set to
- ❌ IAM role
lambda-exechas"*"resource permissions (Line 64)- Remediation: Scope to specific ARNs and actions
Medium Issues (2)
- ⚠️ Missing encryption key rotation for KMS (Line 31) — add
enable_key_rotation = true - ⚠️ CloudTrail not enabled for S3 API calls — enable in
s3.tf
Compliance Status
- CIS 1.12 (Ensure S3 bucket has logging) — ✅ Pass
- CIS 2.1 (Ensure CloudTrail enabled) — ❌ Fail
- CIS 4.1 (Ensure IAM policies attached to groups) — ✅ Pass
What's Included
- SKILL.md: Complete Terraform audit workflow with security frameworks and decision trees
- Security Checklist: Pre-deployment verification template (encryption, IAM, logging, tagging)
- CIS Benchmark Mapping: Terraform-specific controls with remediation code examples
- Compliance Matrix: AWS/Azure/GCP best practices cross-reference
- Risk Assessment Template: Severity scoring and priority matrix
- Remediation Playbook: Common misconfigurations with corrected code blocks
Who It's For
- DevOps Engineers — Review infrastructure code before production deployment
- Cloud Security Engineers — Audit multi-account environments for compliance
- Infrastructure Architects — Validate cloud architecture against security standards
- Platform/SRE Teams — Enforce consistent security policies across teams
- Cloud Governance Teams — Audit and report on infrastructure compliance posture
Best For
- Pre-deployment security reviews — catch issues before terraform apply
- Compliance audits — CIS Benchmarks, SOC 2, PCI-DSS, HIPAA readiness
- IAM hardening — review permissions and enforce least-privilege policies
- Cost optimization analysis — identify expensive configurations and rightsizing
- Multi-cloud infrastructure reviews — validate AWS, Azure, GCP configs against common standards







