reviewing-terraform - Automated Terraform Configuration Review for Security and Best Practices
Reviews Terraform .tf files for security misconfigurations, naming conventions, provider validity, network design, and compliance using tflint, trivy, and MCP-based provider lookups.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Run tflint linting checks
- Run trivy security scanning
- Detect hardcoded secrets in variables
- Review Terraform naming conventions
- Check file organization and structure
- Validate resource attributes via provider docs
- Validate module version pinning
- Validate network and DNS configurations
- Check compliance framework policies
- Generate colored review report
Inputs
- Terraform .tf files or component directory
- .terraform-version file
- version_notes.md reference document
- .tflint.hcl configuration file
- .trivyignore exclusion file
- .compliance.yaml framework declaration
- Existing network infrastructure inventory
Outputs
- Review report with severity-level indicators
- Changelog entries for significant findings
- Architecture decision records (ADR)
- Config decision records for security or convention choices
Requirements
- tflint installed and available in PATH
- trivy installed and available in PATH
- uvx installed and available in PATH
- Docker for running HashiCorp MCP server
- Cursor MCP configuration with terraform-mcp-server and awslabs.terraform-mcp-server
- Cursor auto-run mode with command allowlist for tflint, trivy, docker, and basic shell commands
