Skip to content
check-security logo

Security Checker

check-security

Terraform のセキュリティをチェックする。「セキュリティチェック」「シークレット検出」「セキュリティ監査」「tf セキュリティ」「state のシークレット」「機密情報確認」「セキュリティスキャン」「脆弱性チェック」「ハードコード検出」などで起動。

SKILL.md

Full skill instructions

Security Checker

Terraform 設定とstateのセキュリティチェックを行います。

対応操作

操作トリガー例
全体スキャン「セキュリティチェック」「監査」
コード検査「ハードコード検出」「コード内シークレット」
State 検査「state のシークレット」「state 監査」
IAM 検査「IAM チェック」「権限確認」
ネットワーク検査「SG チェック」「ネットワーク監査」

実行手順

1. コード内のシークレット検出

# AWS キーのパターン検出(AKIA, ASIA, AIDA, AROA 等に対応)
grep -rnE "A(KIA|SIA|IDA|ROA|IPA|GPA|3T)[0-9A-Z]{16}" *.tf **/​*.tf 2>/​dev/​null

# シークレットキーのパターン検出
grep -rn "aws_secret_access_key\s*=" *.tf **/​*.tf 2>/​dev/​null

# パスワードのハードコード検出
grep -rn "password\s*=\s*\"" *.tf **/​*.tf 2>/​dev/​null

# API キーのハードコード検出
grep -rn "api_key\s*=\s*\"" *.tf **/​*.tf 2>/​dev/​null

2. State 内のシークレット検出

# State ファイルの確認
terraform state pull | grep -i "password\|secret\|key\|token" 2>/​dev/​null

3. IAM ポリシーの過剰権限検出

# AdministratorAccess の使用
grep -rn "AdministratorAccess\|arn:aws:iam::aws:policy/​AdministratorAccess" *.tf **/​*.tf 2>/​dev/​null

# ワイルドカード権限
grep -rn '"Action"\s*:\s*"\*"\|"Resource"\s*:\s*"\*"' *.tf **/​*.tf 2>/​dev/​null

# 全リソースアクセス
grep -rn '"*"' *.tf **/​*.tf 2>/​dev/​null | grep -i "action\|resource"

4. ネットワークセキュリティ検出

# 0.0.0.0/​0 からの SSH 許可
grep -B5 -A5 "0.0.0.0/​0" *.tf **/​*.tf 2>/​dev/​null | grep -i "22\|ssh"

# 0.0.0.0/​0 からの全ポート許可
grep -B5 -A5 'from_port\s*=\s*0' *.tf **/​*.tf 2>/​dev/​null

# パブリック S3 バケット
grep -rn "acl\s*=\s*\"public" *.tf **/​*.tf 2>/​dev/​null

5. 暗号化設定の確認

# 暗号化なしの EBS
grep -B10 "aws_ebs_volume\|aws_instance" *.tf **/​*.tf 2>/​dev/​null | grep -v "encrypted\s*=\s*true"

# 暗号化なしの RDS
grep -B10 "aws_db_instance" *.tf **/​*.tf 2>/​dev/​null | grep -v "storage_encrypted\s*=\s*true"

# 暗号化なしの S3
grep -B10 "aws_s3_bucket" *.tf **/​*.tf 2>/​dev/​null | grep -v "server_side_encryption"

6. 出力フォーマット

## セキュリティチェック結果

### 概要

| カテゴリ | 検出数 | 重要度 |
|----------|--------|--------|
| シークレット | {N} | 🔴 高 |
| IAM 過剰権限 | {N} | 🔴 高 |
| ネットワーク | {N} | 🟡 中 |
| 暗号化 | {N} | 🟡 中 |

### 🔴 高リスク

#### シークレットのハードコード

| ファイル | 行 | 問題 |
|----------|-----|------|
| main.tf | 15 | AWS アクセスキーがハードコード |
| ... | ... | ... |

**修正方法**: 環境変数または AWS Secrets Manager を使用

#### IAM 過剰権限

| ファイル | 行 | 問題 |
|----------|-----|------|
| iam.tf | 20 | AdministratorAccess の使用 |
| ... | ... | ... |

**修正方法**: 最小権限の原則に従って権限を制限

### 🟡 中リスク

#### ネットワークセキュリティ

| ファイル | 行 | 問題 |
|----------|-----|------|
| sg.tf | 10 | 0.0.0.0/​0 から SSH 許可 |
| ... | ... | ... |

**修正方法**: 特定の IP 範囲に制限

#### 暗号化未設定

| ファイル | 行 | 問題 |
|----------|-----|------|
| storage.tf | 5 | EBS 暗号化が無効 |
| ... | ... | ... |

**修正方法**: `encrypted = true` を設定

### 推奨事項

1. シークレットは AWS Secrets Manager または環境変数で管理
2. IAM ポリシーは最小権限の原則に従う
3. セキュリティグループは必要最小限のポートのみ許可
4. すべてのストレージで暗号化を有効化

セキュリティベストプラクティス

シークレット管理

# ❌ 悪い例
resource "aws_db_instance" "main" {
  password = "hardcoded-password"  # ハードコード
}

# ✅ 良い例
resource "aws_db_instance" "main" {
  password = var.db_password  # 変数から取得
}

# または
data "aws_secretsmanager_secret_version" "db" {
  secret_id = "db-password"
}

IAM ポリシー

# ❌ 悪い例
resource "aws_iam_role_policy" "admin" {
  policy = jsonencode({
    Statement = [{
      Action   = "*"
      Resource = "*"
    }]
  })
}

# ✅ 良い例
resource "aws_iam_role_policy" "limited" {
  policy = jsonencode({
    Statement = [{
      Action   = ["s3:GetObject", "s3:PutObject"]
      Resource = "arn:aws:s3:::my-bucket/​*"
    }]
  })
}

注意事項

  • ✅ セキュリティチェックは読み取り専用で安全
  • ✅ 定期的にセキュリティ監査を実行
  • ✅ CI/​CD パイプラインにセキュリティチェックを組み込む
  • ⚠️ 検出結果は誤検知の可能性もあるため、内容を確認

More Security skills

supabase logo
Security

supabase

Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...

2.7K 308.9K
View

Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.

98 216.2K
View

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

462 163.8K
View

A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.

462 127.7K
View

Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.

462 125.1K
View

Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.

222 118.2K
View

Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".

31.9K 116.1K
View
cloudflare logo
Security

cloudflare

Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.

3K 110.7K
View

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

253 103K
View
gws-gmail logo
Security

gws-gmail

Send, read, and manage Gmail messages, drafts, labels, and account settings.

31.2K 78.9K
View

Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.

94 72.3K
View
gws-shared logo
Security

gws-shared

Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.

31.2K 63.4K
View

Security AI tools

StarByFace logo
Security

StarByFace

Discover your celebrity doppelgänger with StarByFace!

Free
View
GeoSpy logo
Security

GeoSpy

GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams

Free
View

Detect AI-generated voices to protect against audio fraud.

Paid
View

Ensure Your Content's Originality with AI Plagiarism Checker

Freemium
View
Img Upscaler logo
Security

Img Upscaler

Upscale images by 400% without quality loss

Freemium
View
AICheatCheck logo
Security

AICheatCheck

Accurately Detect AI-Generated Content with TheChecker.AI

Free
View
D
Security

Detect GPT

Chrome extension that detects and flags AI-generated content

Free
View