Review agent · Infra & pipeline

Infrastructure & IaC

Reviews Terraform, Helm, Ansible and server config for insecure defaults and exposure.

deploy/app.yaml1env:2 DEBUG: "true"3 CORS_ORIGINS: "*"4 TLS_VERIFY: "false"IaCwhat this review answersDebug mode on in production?Permissive CORS or TLS disabled?Scoped to local dev or test?$ verdict REAL ISSUE$ fix hardened defaults, scoped CORS▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Misconfiguration is OWASP A05 and one of the most common root causes of cloud incidents — debug mode in production, wide-open CORS, TLS checks turned off.

IaC scanners produce long lists of checks, many of which don't apply to your environment. This agent weighs each one in context so the exposure that matters is at the top.

What it checks

  • Debug or verbose modes enabled in production config
  • Permissive CORS
  • Disabled TLS or certificate verification
  • Open management ports and unhardened defaults

When it marks a finding as a likely false positive

  • The setting is scoped to local development or test
  • Exposure is intentional and restricted

The fix it suggests

  • Hardened defaults
  • Enforced TLS
  • Scoped CORS and closing unneeded ports

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Which IaC formats are scanned?

Trivy's config scanner covers Dockerfiles, Terraform, Kubernetes manifests and docker-compose; findings are then routed to this agent or the cloud and container agents.

Related agents

  • Cloud security — Checks cloud resources for public exposure, wildcard IAM and long-lived keys.
  • Container & Kubernetes — Checks Dockerfiles and Kubernetes manifests for root, privileged and host-level access.
  • CI/CD pipeline — Checks pipelines for leaked secrets, untrusted code execution and over-broad tokens.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Infrastructure & IaC agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free