{"slug":"iac-misconfig-review","source_name":"iac-misconfig-review","name":"IaC Misconfig Review","description":"Reviews infrastructure-as-code and container config — Terraform, a Kubernetes manifest, a Dockerfile, a docker-compose file — for insecure defaults and misconfigurations: containers that run as root or privileged, host namespace/volume escapes, security groups open to the world, public object storage, storage left unencrypted, plaintext secrets, and metadata-service exposure. Names each finding and its fix. Use when asked to review or security-check an existing IaC or container config before it ships. Do NOT use for writing a fresh Dockerfile from scratch (that is a separate authoring task), for reviewing the breadth of an IAM/RBAC permission grant, or for debugging a container already running in production.","version":1,"lift":{"pass_rate_delta_pts":null,"pass_rate_pct":37.5,"total_cases":16,"passed_cases":6,"tokens_delta_pct":708.6,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.5-flash","grading_method":"judged","completed_at":"2026-07-10T04:15:02.523628+00:00"},"skill_score":0.9927,"benchmark_models":[{"model":"gemini-3.5-flash","headline":false,"delta_pts":null,"with_pass_pct":null,"without_pass_pct":null,"tokens_delta_pct":708.6,"turns_delta_pct":0,"total_cases":16,"cases_aggregated":16,"verdict":"mixed","never_hurt":true,"completed_at":"2026-07-10T04:15:02.523628+00:00","run_id":"7038b87a-2938-48fb-a891-e60f49d0358d","version_number":1,"is_latest_version":true,"gate":"not_comparable"}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":false},"license":null,"install_count":2,"manifest_hash":"3118ef6b641974b405da063cd142c60f4faf565de8ee78a77c16977480eeb718","raw_url":"https://app.decimal.ai/s/iac-misconfig-review/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/iac-misconfig-review"}