
Terraform Plan Reviewer
Review Terraform plans for security & cost risks
What You Can Do
You can analyze Terraform execution plans to identify security vulnerabilities, cost optimization opportunities, and AWS best practice violations before resources are deployed. This skill reviews your Terraform code for IAM misconfiguration, unencrypted resources, over-provisioned instances, and architectural antipatterns—then provides specific remediation steps for each finding.
Features
Detects IAM policy overpermissions, unencrypted storage/databases, exposed credentials, and public resource access
Identifies over-provisioned instances, unused resources, inefficient storage classes, and recommends right-sizing
Checks against AWS Well-Architected Framework pillars (security, reliability, performance, cost, operations)
Ensures resources comply with common standards (encryption, logging, tagging, VPC isolation)
Provides specific Terraform code changes to fix each issue, not just problem statements
Maps resource relationships and flags circular dependencies or cascade risks
Analyzes what's being created, modified, or destroyed and potential consequences
Example Output
Security Findings
HIGH — IAM Role lacks explicit deny policies
- Resource:
aws_iam_role.lambda_execution - Issue:
s3:*permission on all buckets violates principle of least privilege - Fix: Scope to specific bucket ARN —
arn:aws:s3:::my-app-uploads/*
MEDIUM — RDS database not encrypted at rest
- Resource:
aws_db_instance.main - Issue:
storage_encrypted = falseallows unencrypted data - Fix: Add
storage_encrypted = trueand enable encrypted backups
Cost Optimizations
- EC2 instance type: t3.large ($60/mo) → t3.small ($13/mo) — 78% savings
- RDS instance class: db.r5.2xlarge → db.r5.large — saves $1,200/month
- S3 storage class: STANDARD → Intelligent-Tiering — ~30% savings with auto-archival
AWS Best Practices
✓ VPC endpoints configured for private API calls ✓ CloudTrail logging enabled
- ⚠️ NAT Gateway in single AZ (single point of failure) — add second AZ
- ⚠️ Backup retention too aggressive (90 days) — reduce to 30 days
What's Included
- SKILL.md: Complete Terraform review workflow, evaluation criteria, and remediation patterns
- Security Checklist: 25-point validation template (IAM, encryption, network, logging)
- Cost Optimization Guide: Common AWS savings patterns with Terraform examples
- AWS Best Practices Reference: Well-Architected Framework mapping and checks
- Review Report Template: Structured output format (findings, recommendations, impact)
- Remediation Examples: Code snippets for common fixes (IAM scoping, encryption, scaling)
Who It's For
- DevOps engineers — Catch infrastructure misconfigurations before production deploys
- Cloud architects — Validate multi-environment designs against AWS best practices
- Security engineers — Audit IAM, encryption, and compliance in infrastructure code
- Engineering leads — Review infrastructure changes during code review process
- SREs — Ensure operational best practices in infrastructure deployments
Best For
- Pre-deployment Terraform plan reviews in CI/CD pipelines
- Security audits of infrastructure-as-code changes
- Cost optimization analysis before provisioning resources
- AWS best practices validation across dev/staging/prod environments
- Knowledge transfer on infrastructure security patterns







