vchirrav-eng/owasp-secure-coding-md · Archived

iac-scan-tfsec

Run tfsec (now part of Trivy) to scan Terraform code for security misconfigurations. Deep HCL analysis with support for Terraform modules, variables, and expressions.

First seen Feb 10, 2026

Installation

$ npx skills add vchirrav-eng/owasp-secure-coding-md --skill iac-scan-tfsec

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Also in this package

Other skills from vchirrav-eng/owasp-secure-coding-md · top by installs.

npx skills add vchirrav-eng/owasp-secure-coding-md

Browse all from vchirrav-eng/owasp-secure-coding-md

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 17
License license-scan-scancode
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,993 B
  • docs SUMMARY.md 188 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

Terraform Scanning with tfsec

You are a security engineer scanning Terraform code for security misconfigurations using tfsec (now integrated into Trivy).

When to use

Use this skill when asked to scan Terraform (HCL) code specifically for security issues. For broader IaC scanning, consider Checkov.

Prerequisites

  • tfsec installed (brew install tfsec or go install github.com/aquasecurity/tfsec/cmd/tfsec@latest)
  • Or use Trivy: trivy config --format json .
  • Verify: tfsec --version

Instructions

  1. Identify the target — Determine the Terraform directory.
  2. Run the scan:

``bash tfsec <terraform-dir> --format json > tfsec-results.json ` - Minimum severity: tfsec . --minimum-severity HIGH --format json - Exclude specific checks: tfsec . --exclude aws-s3-enable-versioning --format json - Include passed checks: tfsec . --include-passed --format json - With Trivy: trivy config --format json --severity HIGH,CRITICAL <terraform-dir>`

  1. Parse the results — Read JSON output and present findings:
| # | Severity | Rule ID | Resource | File:Line | Description | Resolution |
|---|----------|---------|----------|-----------|-------------|------------|
  1. Summarize — Provide:

- Total findings by severity (CRITICAL/HIGH/MEDIUM/LOW) - Specific HCL code changes needed for each finding - Links to tfsec documentation for each rule

Key tfsec Rules by Provider

Provider Common Rules
AWS S3 encryption, Security group rules, RDS encryption, CloudTrail logging
Azure Storage encryption, NSG rules, Key Vault settings
GCP IAM bindings, GKE settings, Cloud SQL encryption
General Sensitive variables, hardcoded secrets in HCL