CtrlK
BlogDocsLog inGet started
Tessl Logo

iac-security

Infrastructure as Code security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM. Detects misconfigurations, security risks, and compliance violations before deployment. Use when: - User asks to scan Terraform files or modules - User mentions "infrastructure security" or "IaC scan" - User is working with Kubernetes manifests - User asks about CloudFormation or ARM template security - Agent is generating or modifying infrastructure code

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable skill with an exemplary phased workflow and verification loop, held back by a progressive-disclosure failure: two reference files exist in the bundle but are never linked from the body, and representative fixes are inlined instead. Conciseness and actionability are good with only minor trimming opportunities.

Suggestions

Add explicit links in Phase 4 to the existing bundle files, e.g. "Terraform: see [terraform-security-patterns.md](references/terraform-security-patterns.md)" and "Kubernetes: see [kubernetes-security-patterns.md](references/kubernetes-security-patterns.md)", so the detailed patterns are discoverable.

Replace the inlined remediation snippets in Phase 4 with one representative example plus the reference links, keeping SKILL.md as an overview and moving the per-resource fix catalog entirely into the references.

Add trigger terms for the supported formats the description omits (.tf files, K8s/Helm, Serverless) so the description matches the body's actual coverage.

DimensionReasoningScore

Conciseness

The body is largely lean — tables, parameterized scan invocations, and ready fixes with no concept explanations of what Terraform or Kubernetes is. Score 4 rather than 5 because the Phase 4 remediation snippets (S3 public access block, secure pod spec) duplicate content in the reference files, and the summary templates with X/Y/Z placeholders add bulk that could be tightened.

4 / 5

Actionability

Concrete tool invocations with named parameters ("Run snyk_iac_scan with: path... var_file... scan: 'planned-values'"), executable terraform plan/show commands, complete HCL/YAML fixes, and an error-handling table with specific resolutions. Not 5 because the core scan instructions use unfilled placeholders and pseudocode-style parameter blocks rather than fully specified calls for a concrete case.

4 / 5

Workflow Clarity

A clear five-phase sequence (Discovery → Execute Scan → Analyze → Remediation → Verification) with an explicit re-scan verification loop, before/after improvement reporting, and remaining-issue documentation. The error-handling table provides recovery paths, matching the anchor's "explicit validation steps; feedback loops for error recovery".

5 / 5

Progressive Disclosure

The body is well-sectioned but never mentions the two existing reference files (references/terraform-security-patterns.md, references/kubernetes-security-patterns.md), so the bundle's detailed patterns are undiscoverable from SKILL.md. The inline Phase 4 examples partially duplicate that reference content — "references present but not clearly signaled; content that should be separate is inline" fits better than the 4 anchor, which requires references to be mostly clearly signaled.

3 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities across four named platforms, explicit multi-case triggers, and third-person voice. Its only weakness is keyword coverage that omits extensions and synonyms (.tf, K8s, Helm) for supported formats.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ("security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM", "Detects misconfigurations, security risks, and compliance violations before deployment") with comprehensive platform coverage. Not the 4 anchor because coverage spans four named IaC platforms plus three distinct detection actions rather than having minor gaps.

5 / 5

Completeness

Explicitly answers both questions: what ("security scanning... Detects misconfigurations, security risks, and compliance violations") and when (five concrete "Use when" triggers including user-ask, user-mention, and agent-action cases). Matches the score-5 anchor's structure of a clear what followed by explicit trigger phrases.

5 / 5

Trigger Term Quality

Good natural keyword coverage: "scan Terraform files or modules", "infrastructure security", "IaC scan", "Kubernetes manifests", "CloudFormation or ARM template security". Not 5 because common variations are missing — no file extensions (.tf, .yaml), no "K8s", "Helm", "Serverless", or "compliance" triggers despite the body supporting those formats.

4 / 5

Distinctiveness Conflict Risk

Clear niche (pre-deployment IaC security scanning) with distinct platform-named triggers; unlikely to fire for general document or coding skills. The "Agent is generating or modifying infrastructure code" bullet has slight overlap with IaC authoring skills, but the dominant framing is unmistakably security scanning, so the 5 anchor fits better than 4.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.