{"uid":"cap_kqiw4UcUnOHm1ooldoQby","slug":"terraform-iam-risk-scanner-4d864177","name":"Terraform IAM Risk Scanner","description":"Scan Terraform for IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, and missing encryption hints.","url":"https://x402-hono-api.inraby.workers.dev/api/v1/terraform-iam-risk-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"cloud":{"type":"string","description":"Cloud provider hint (aws recommended)"},"terraform":{"type":"string","description":"Terraform HCL contents"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_rpPzvsgvB65-XLkusEfLm","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans Terraform HCL for IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, and missing encryption hints","exampleAgentPrompt":"Can you scan this Terraform HCL for security risks — specifically IAM wildcards, publicly exposed S3 or RDS resources, open security groups, overly broad assume-role trust, and missing encryption? The cloud provider is AWS.","exampleUseCases":null,"resultDescription":"A structured list of security findings categorized by risk type (IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, missing encryption), each describing the detected issue and its location within the submitted Terraform HCL.","failureModes":["Invalid or unparseable Terraform HCL returns a parse error","Missing terraform field returns a 400 bad request","Empty HCL content may return no findings rather than an error","Non-AWS cloud provider hints may reduce detection accuracy","Very large HCL files may timeout or be truncated","Payment not sent or insufficient USDC returns 402 Payment Required"],"whenToPreferThis":"Use this endpoint when you need a focused, automated security review of Terraform HCL specifically targeting IAM and infrastructure exposure risks (wildcards, public S3/RDS, open security groups, encryption gaps). Prefer this over generic linting tools when the concern is cloud security posture rather than syntax or style. Complements the sibling IAM policy JSON auditor when the configuration source is Terraform rather than raw policy JSON.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:44:00.725Z","isFirstParty":false}