Cloud Config Audit — Security skill for Claude Code
Assess infrastructure-as-code security with offline scanning and evidence-based finding review.
How to install Cloud Config Audit
Installs to ~/.claude/commands/openshift-traust-cloud-config-audit.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/openshift/traust/HEAD/.claude/commands/cloud-config-audit.md -o ~/.claude/commands/openshift-traust-cloud-config-audit.md Restart Claude Code, or start a new session, for it to be picked up.
What Cloud Config Audit does
description: "Assess infrastructure-as-code security with offline scanning and evidence-based finding review."
Run the cloud config audit skill for the IaC checkout given in $ARGUMENTS.
Follow harnessing/3-audit/cloud-config-audit/SKILL.md exactly: Layer-1 deterministic facts via the pinned Checkov engine fully offline (run_checkov.py — no cloud API calls, no platform key, secrets framework skipped), then bounded Layer-2 disposition (dedupe, cited suppressions, rubric-based severity, C
Alternatives in Security
- Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Lintai
Offline-first, precision-first security linter for SKILLS, MCP, plugins, configs and other AI infrastructure.
Claude Code Dev Agents
A comprehensive collection of specialized Claude Code subagents for software development lifecycle. Domain-agn
Seraph
Multi-agent cloud governance system that reviews AWS infrastructure changes for security, cost, and compliance
Devsecops
Audit pipelines, IaC, or cloud config for security risk via guided intake - domain, stack, config context, fra
Ops Engineering Skills
Open-source, cross-agent Agent Skills for DevOps, DevSecOps, Cloud, Kubernetes/platform engineering, CI/CD too
Cleanup Repo
Read-only repo audit for stale/orphaned files, tracked cruft, accidentally-committed secrets, empty files, and
Related Agents
Wp Audit Security
Security auditor — code scanning, wp-config validation, AIOS configuration, security headers
Infra Platform Reviewer
Reviewer for infrastructure-as-code and platform — Terraform/Bicep quality, state, containers, drift, and blas
Ad Security Reviewer
Use this agent when you need to audit Active Directory security posture, evaluate privilege escalation risks,