{"uid":"cap_JhpdS_Lo4OPVfnwGL3zuQ","slug":"iac-static-misconfiguration-scanner-d9998761","name":"IaC Static Misconfiguration Scanner","description":"Static misconfiguration scan of an infrastructure-as-code config: Terraform (plan JSON or HCL), Kubernetes / Helm, Dockerfile, docker-compose or CloudFormation. Detects public storage, open security groups, unencrypted data at rest, over-broad IAM, privileged / root containers, host mounts and more. Returns a verdict (pass, caution, block), a 0-100 risk score and per-finding rule, severity, resource, location and fix hint. Security indicators, not a guarantee.","url":"https://api.agentstools.dev/iac/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"format":{"enum":["auto","terraform","terraform-plan","kubernetes","dockerfile","docker-compose","cloudformation"],"type":"string","description":"Config format, or auto to detect from the content"},"content":{"type":"string","description":"The IaC config text to scan (one or many resources)"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_deZAjtjGiYMXpnAkle4Z0","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a static security scan of infrastructure-as-code configs (Terraform, Kubernetes, Dockerfile, docker-compose, CloudFormation) and returns a verdict, risk score, and per-finding details with fix hints.","exampleAgentPrompt":"Can you scan this Terraform HCL config for security misconfigurations and tell me the risk score, verdict, and any specific findings with fix hints? Here's the config: [paste HCL]","exampleUseCases":[{"title":"Pre-deploy Terraform security gate","prompt":"Before I apply this Terraform plan, scan it for issues like public S3 buckets, open security groups, or unencrypted volumes — give me the verdict and risk score so I know if it's safe to deploy."},{"title":"Dockerfile privilege and root container check","prompt":"Check this Dockerfile for security problems like running as root, privileged mode, or dangerous host mounts, and tell me what needs to be fixed and how severe each issue is."},{"title":"Kubernetes manifest IAM and network audit","prompt":"I have a Kubernetes manifest I'm about to push to production — can you scan it for things like over-broad permissions, host path mounts, or privileged containers and give me a full list of findings with fix suggestions?"}],"resultDescription":"Returns a verdict (pass, caution, or block), a 0–100 risk score, and a list of per-finding objects each containing the rule name, severity level, affected resource, location within the config, and a fix hint. Serves as security signal, not a compliance guarantee.","failureModes":["Unsupported or malformed config format causes parsing failure","Auto-detection fails for ambiguous or mixed-format configs","Very large config payloads may time out or be rejected","False negatives: novel or complex misconfigurations may not be detected","False positives possible on non-standard but intentional configurations"],"whenToPreferThis":"Choose this endpoint when you need a fast, automated security pre-check of IaC configs (Terraform, Kubernetes, Dockerfile, docker-compose, CloudFormation) before deployment. Ideal for CI/CD pipeline gates, agent-driven DevSecOps workflows, or on-demand config audits where a structured verdict and actionable per-finding fix hints are needed at low cost ($0.02/call).","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:01:40.056Z","isFirstParty":false}