Inspiration

I built the IaC Security Review Agent for the AWS Agents for Humans 2026 Hackathon.

I was already interested in cloud security, DevOps, and Infrastructure as Code, and I wanted to build something that connected those interests with agentic AI.

Terraform makes infrastructure repeatable, but insecure configurations can be repeated too. I wanted to explore whether an AI agent could make Terraform security reviews more useful to developers, rather than simply acting as another chatbot that answers questions about AWS.

The idea became: scan Terraform for concrete security issues, then use an agent to turn those findings into useful, developer-friendly feedback.

What it does

The IaC Security Review Agent analyzes Terraform configuration files for common security issues and produces structured findings.

The deterministic security scanner currently checks for:

  • Public S3 ACLs
  • Disabled S3 public access protection
  • Open network ingress
  • Wildcard IAM permissions
  • Unencrypted storage
  • Hardcoded secrets
  • Missing S3 access logging

Each finding includes information such as its rule ID, severity, evidence, line number, and resource context.

The Strands agent then receives these structured findings and uses an LLM to explain the issues and suggest remediation in a PR-review style.

The important distinction is that the LLM is not responsible for deciding what is vulnerable. The deterministic scanner handles detection, while the agent handles explanation and developer-facing feedback.

How we built it

The project was built in Python using the Strands Agents SDK.

The workflow is:

Terraform configuration
        |
        v
Deterministic Python security checks
        |
        v
Structured findings
        |
        v
Strands Agent
        |
        v
LLM via OpenRouter
        |
        v
Developer-friendly security review

I built the security scanner first, using pattern and resource-based checks against Terraform files. I then structured its output so the agent could consume consistent findings instead of having to interpret raw Terraform on its own.

For the AI layer, I integrated Strands with an OpenAI-compatible model interface through OpenRouter.

I also created intentionally insecure and secure Terraform examples and added automated tests with pytest to validate the deterministic security layer independently from the AI layer.

Challenges we ran into

One of the biggest challenges was the development environment. I had multiple Python installations on my machine, which caused pip to point to the wrong Python version. I had to work through the virtual environment and dependency setup before getting everything installed correctly.

The model integration also required some iteration. My initial approach used a different model provider, but access and cost considerations made that approach less practical for my current setup. I eventually moved to OpenRouter through Strands' OpenAI-compatible integration.

Another challenge was deciding how much responsibility to give the LLM. It was tempting to have the model inspect the entire Terraform file and identify vulnerabilities itself, but that would make the security logic harder to test and trust.

That led to one of the most important architectural decisions in the project: keep security detection deterministic and use AI where it adds the most value.

Accomplishments that we're proud of

I'm proud that the project evolved from a simple idea into a working, tested agent architecture.

The deterministic scanner currently detects 12 findings in the intentionally insecure Terraform example:

CRITICAL   1
HIGH       9
MEDIUM     2

The secure example produces:

Static findings: 0

No static findings detected.

I also added automated tests for the security rules, with the current test suite passing 10 tests.

Most importantly, I was able to build the project around a clear separation between deterministic security analysis and AI-assisted explanation. That makes the system easier to understand, test, and extend.

What we learned

The biggest lesson I learned was that building with AI doesn't mean giving the entire problem to an AI model.

An agent can be more useful when the model has a clearly defined role and reliable information to work with.

In this project, deterministic checks are better suited to identifying known security patterns, while an LLM is better suited to explaining those findings in natural language and suggesting how a developer might address them.

I also learned that building an agent is much more than writing a prompt. Environment setup, dependencies, model integration, structured data, testing, failure handling, and defining the agent's boundaries all matter.

What's next for IaC Security Review Agent

There is still a lot I want to improve.

The next steps include:

  • Replacing regex-based analysis with proper Terraform/HCL parsing
  • Expanding the security rule set
  • Improving resource and code context in findings
  • Adding GitHub pull request integration
  • Integrating the reviewer into CI/CD pipelines
  • Improving the quality and consistency of AI-generated remediation suggestions

The long-term goal is to make infrastructure security feedback part of the development workflow, so security issues can be identified and explained while infrastructure is still being developed rather than after deployment.

Built With

Share this project:

Updates

Submission history