CtrlK
BlogDocsLog inGet started
Tessl Logo

iac-security

Infrastructure as Code security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM. Detects misconfigurations, security risks, and compliance violations before deployment. Use when: - User asks to scan Terraform files or modules - User mentions "infrastructure security" or "IaC scan" - User is working with Kubernetes manifests - User asks about CloudFormation or ARM template security - Agent is generating or modifying infrastructure code

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with a well-sequenced, validated workflow, but it underuses progressive disclosure: large remediation pattern catalogs are inlined while matching reference files sit unlinked, and some reporting templates add length without proportional value.

Suggestions

Replace the inlined Terraform/Kubernetes/CloudFormation remediation code blocks with concise pointers to references/terraform-security-patterns.md and references/kubernetes-security-patterns.md, keeping only one representative example inline.

Trim or move the full 'IaC Security Scan Results' and 'Fix Verification' report templates into a reference file, summarizing the expected structure in a few lines instead.

Add a short 'References' section that explicitly signals each bundle file so the overview stays a lean entry point to one-level-deep detail.

DimensionReasoningScore

Conciseness

The body is mostly efficient and phase-organized with little concept-padding, but it inlines full Terraform/Kubernetes/CloudFormation remediation code catalogs that duplicate the bundled references/, plus repetitive summary/reporting templates that could be tightened, so it does not reach lean efficiency.

3 / 5

Actionability

Provides fully executable, copy-paste-ready guidance: concrete snyk_iac_scan invocations with parameters (path, var_file, scan, rules), runnable terraform plan/show bash, complete HCL/YAML secure-config examples, and an error-to-solution table covering common cases.

5 / 5

Workflow Clarity

A clear five-phase sequence (Discovery, Scan, Analyze, Remediation, Verification) with an explicit validation checkpoint in Phase 5 (re-scan, regenerate plan, before/after reporting) and an error-handling table, satisfying explicit validation steps and feedback loops for this deployment-blocking skill.

5 / 5

Progressive Disclosure

Two bundle files exist under references/ (kubernetes-security-patterns.md, terraform-security-patterns.md) but the body never links to them, and the pattern catalogs that clearly belong in those files are inlined instead, leaving references present but unsignaled and content that should be separate kept inline.

3 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it concisely states what the skill does across four named IaC platforms and provides explicit, natural 'Use when' trigger guidance. Minor gains would come from adding file extensions and a couple of action synonyms, but it already clearly separates from generic skills.

DimensionReasoningScore

Specificity

Names the domain and lists several concrete actions — 'security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM' and 'Detects misconfigurations, security risks, and compliance violations before deployment' — with only minor coverage gaps (remediation/reporting not stated in the what-clause), fitting the anchor just below fully comprehensive.

4 / 5

Completeness

Explicitly answers both 'what' (scanning four IaC platforms, detecting misconfigurations and compliance violations) and 'when' via five concrete 'Use when' trigger clauses, matching the top anchor for completeness.

5 / 5

Trigger Term Quality

Good natural keyword coverage across 'scan Terraform files', 'infrastructure security', 'IaC scan', 'Kubernetes manifests', 'CloudFormation', and 'ARM template security', but missing file extensions like .tf/.yaml and some common synonyms, so it sits between anchor 4 and 5 rather than at 5.

4 / 5

Distinctiveness Conflict Risk

Scoped to IaC security scanning across named platforms (Terraform, K8s, CloudFormation, ARM) with distinct triggers, giving it a clear niche with minimal conflict risk against unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.