{"uid":"cap_HxnyV4qKGEsziAtnCeIrh","slug":"iac-static-misconfiguration-scanner-f18ec87c","name":"IaC Static Misconfiguration Scanner","description":"Static misconfiguration scan of an infrastructure-as-code config: Terraform (plan JSON or HCL), Kubernetes / Helm, Dockerfile, docker-compose or CloudFormation. Detects public storage, open security groups, unencrypted data at rest, over-broad IAM, privileged / root containers, host mounts and more. Returns a verdict (pass, caution, block), a 0-100 risk score and per-finding rule, severity, resource, location and fix hint. Security indicators, not a guarantee.","url":"https://payai.agentstools.dev/iac/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"format":{"enum":["auto","terraform","terraform-plan","kubernetes","dockerfile","docker-compose","cloudformation"],"type":"string","description":"Config format, or auto to detect from the content"},"content":{"type":"string","description":"The IaC config text to scan (one or many resources)"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_KBs-P7AqvLE72OXVh3M5s","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically scans infrastructure-as-code configs (Terraform, Kubernetes, Dockerfile, docker-compose, CloudFormation) for security misconfigurations, returning a verdict, risk score, and per-finding details with fix hints.","exampleAgentPrompt":"Scan this Terraform HCL for security misconfigurations — I want to know if there are any open security groups, public storage, or over-broad IAM policies, and what the overall risk score is.","exampleUseCases":[{"title":"Pre-deploy Terraform plan security check","prompt":"Before I apply this Terraform plan, scan it for security issues like public S3 buckets, unencrypted RDS, or overly permissive IAM roles and tell me if I should block the deployment."},{"title":"Kubernetes manifest security audit","prompt":"Check this Kubernetes deployment manifest for problems like privileged containers, host path mounts, or missing resource limits — give me a risk score and tell me what to fix."},{"title":"Dockerfile root and privilege scan","prompt":"Scan my Dockerfile and tell me if it runs as root, has any privileged instructions, or other security misconfigs I should fix before pushing to production."}],"resultDescription":"Returns a verdict string (pass, caution, or block), a 0-100 integer risk score, and a list of per-finding objects each containing the rule name, severity, affected resource name, file location, and a plain-English fix hint. These are security indicators, not guarantees.","failureModes":["Unsupported or malformed config content returns a parsing error","Auto-detection may misidentify format if content is ambiguous — specify format explicitly to avoid","Very large configs may be truncated or timeout","Some niche Terraform providers or custom Kubernetes CRDs may not have rule coverage","False positives possible for intentionally public resources (e.g., CDN buckets)"],"whenToPreferThis":"Use this endpoint when you need fast, per-finding security feedback on IaC configs before deployment, CI gate decisions, or due-diligence audits. Prefer it over generic linters when you need a structured verdict and risk score across multiple IaC formats (Terraform HCL and plan JSON, Kubernetes/Helm, Dockerfile, docker-compose, CloudFormation) in a single call. It is not a runtime security scanner — use it for static config analysis only.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:47:02.865Z","isFirstParty":false}