Judged in context
A wildcard role matters more when the service behind it takes untrusted input. Configuration is weighed against the application's deployment context, entry points, and trust boundaries, not scored in isolation.
The same agents that trace your application code review Terraform, CloudFormation, Kubernetes, Helm, Docker, and CI workflow files, and weigh every setting against what the application actually exposes.
| Severity | Finding |
|---|---|
| C9.3 | PR title interpolated into a workflow shell stepPipeline injection.github/workflows/preview.yml:24 |
| H8.2 | Role grants s3:* on every bucketIAMterraform/iam.tf:88 |
| H7.8 | Worker pod runs privileged with host PIDKubernetesk8s/worker.yaml:31 |
| M5.9 | Exports bucket allows public readStorageterraform/s3.tf:12 |
| 20 | steps: | |
| 21 | - uses: actions/checkout@v4 | |
| 22 | - name: Label preview | |
| 23 | run: | | |
| 24 | ! echo "Preview: ${{ github.event.pull_request.title }}" |
Find Terraform, CloudFormation, Kubernetes, Helm, Docker, and pipeline files anywhere in the repository.
Check identity, storage, network, container, and pipeline settings.
Weigh each issue against the services and data it exposes.
Patch the configuration in a pull request and confirm on the next scan.
A wildcard role matters more when the service behind it takes untrusted input. Configuration is weighed against the application's deployment context, entry points, and trust boundaries, not scored in isolation.
Configuration findings carry the same file and line, CVSS vector, trace, and remediation guidance as code findings, in the same workspace and the same pull requests.
Review is done by the agents rather than a fixed rule set, so unusual layouts and new resource types do not wait on a rule update.
Workflow files get the same scrutiny as application code, starting with untrusted event data that reaches a shell step.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
