Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Expert guidance for Checkov, the static analysis tool for infrastructure-as-code that scans Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, and ARM templates for security misconfigurations and compliance violations. Helps developers integrate Checkov into CI/CD pipelines and write custom policies.
.claude/skills/terminalskills-checkov/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | 335% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 198% | 0% |
| case-20 | ✓→✗ | ▼ Worse | 160% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 231% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 351% | 0% |
Checkov, the static analysis tool for infrastructure-as-code that scans Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, and ARM templates for security misconfigurations and compliance violations. Helps developers integrate Checkov into CI/CD pipelines and write custom policies.
bash# Install pip install checkov # Scan Terraform files checkov -d ./terraform/ # Scan Kubernetes manifests checkov -d ./k8s/ --framework kubernetes # Scan Dockerfiles checkov -f Dockerfile --framework dockerfile # Scan with specific checks checkov -d . --check CKV_AWS_18,CKV_AWS_21 # Only specific checks # Skip specific checks checkov -d . --skip-check CKV_AWS_18 # Skip S3 logging check # Output formats checkov -d . -o json # JSON for CI/CD checkov -d . -o sarif # SARIF for GitHub Security tab checkov -d . -o junitxml # JUnit for test reports
hcl# Terraform — Checkov flags these misconfigurations: # ❌ CKV_AWS_18: S3 bucket without access logging resource "aws_s3_bucket" "data" { bucket = "my-data-bucket" # Missing: logging { target_bucket = "..." } } # ❌ CKV_AWS_145: RDS without encryption resource "aws_db_instance" "main" { engine = "postgres" instance_class = "db.t3.medium" # Missing: storage_encrypted = true } # ❌ CKV_AWS_24: Security group with 0.0.0.0/0 on SSH resource "aws_security_group_rule" "ssh" { type = "ingress" from_port = 22 to_port = 22 cidr_blocks = ["0.0.0.0/0"] # Open SSH to the world } # ❌ CKV_AWS_79: EC2 without metadata service v2 resource "aws_instance" "web" { ami = "ami-12345" instance_type = "t3.micro" # Missing: metadata_options { http_tokens = "required" } }
yaml# Kubernetes — Checkov flags these: # ❌ CKV_K8S_1: Container running as root # ❌ CKV_K8S_8: No liveness probe # ❌ CKV_K8S_9: No readiness probe # ❌ CKV_K8S_12: No memory limit # ❌ CKV_K8S_13: No memory request # ❌ CKV_K8S_20: Privileged container # ❌ CKV_K8S_28: No CPU limit # ❌ CKV_K8S_37: No capabilities drop apiVersion: apps/v1 kind: Deployment spec: template: spec: containers: - name: app image: myapp:latest # ❌ CKV_K8S_14: Using 'latest' tag # Missing: all security context, probes, and resource limits
python# custom_checks/s3_naming.py — Custom Checkov policy in Python from checkov.terraform.checks.resource.base_resource_check import BaseResourceCheck from checkov.common.models.enums import CheckResult, CheckCategories class S3BucketNamingConvention(BaseResourceCheck): def __init__(self): name = "S3 bucket name must start with company prefix" id = "CKV_CUSTOM_1" supported_resources = ["aws_s3_bucket"] categories = [CheckCategories.CONVENTION] super().__init__(name=name, id=id, categories=categories, supported_resources=supported_resources) def scan_resource_conf(self, conf): bucket_name = conf.get("bucket", [""])[0] if bucket_name.startswith("mycompany-"): return CheckResult.PASSED return CheckResult.FAILED check = S3BucketNamingConvention()
yaml# custom_checks/require_tags.yaml — Custom policy in YAML (simpler) metadata: id: "CKV_CUSTOM_2" name: "All resources must have 'team' and 'environment' tags" category: "CONVENTION" definition: cond_type: "attribute" resource_types: - "aws_instance" - "aws_s3_bucket" - "aws_rds_cluster" attribute: "tags.team" operator: "exists"
yaml# .github/workflows/security.yml - name: Checkov IaC Scan uses: bridgecrewio/checkov-action@v12 with: directory: terraform/ framework: terraform output_format: sarif output_file_path: checkov.sarif soft_fail: false # Fail the pipeline on findings skip_check: CKV_AWS_18 # Skip known exceptions - name: Upload SARIF uses: github/codeql-action/upload-sarif@v3 with: sarif_file: checkov.sarif
bashpip install checkov # Or via Docker docker run -v $(pwd):/tf bridgecrew/checkov -d /tf # Or via Homebrew brew install checkov
User request:
I have a Node.js API and a React frontend running in Docker. Set up Checkov for monitoring/deployment.The agent creates the necessary configuration files based on patterns like # Install, sets up the integration with the existing Docker setup, configures appropriate defaults for a Node.js + React stack, and provides verification commands to confirm everything is working.
User request:
Checkov is showing errors in our what checkov catches. Here are the logs: [error output]The agent analyzes the error output, identifies the root cause by cross-referencing with common Checkov issues, applies the fix (updating configuration, adjusting resource limits, or correcting syntax), and verifies the resolution with appropriate health checks.
--soft-fail to see findings without blocking; gradually enable hard-fail as you fix issues#checkov:skip=CKV_AWS_18:Logging handled by org-level trail--baseline to establish a baseline of existing findings; only flag new issues in PRs| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 3,343 | 2,505 | -25% | 1 | 1 | 0% | 659 | 2,184 | +231% | 0 | 0 | — |
case-02 | pass→pass | 2,511 | 2,129 | -15% | 1 | 1 | 0% | 461 | 2,079 | +351% | 0 | 0 | — |
case-03 | pass→pass | 2,757 | 2,522 | -9% | 1 | 1 | 0% | 550 | 2,264 | +312% | 0 | 0 | — |
case-04 | pass→pass | 2,947 | 2,682 | -9% | 1 | 1 | 0% | 573 | 2,277 | +297% | 0 | 0 | — |
case-21 | pass→pass | 13,901 | 13,316 | -4% | 1 | 1 | 0% | 2,738 | 4,061 | +48% | 0 | 0 | — |
case-05 | pass→pass | 7,373 | 2,868 | -61% | 1 | 1 | 0% | 1,386 | 2,305 | +66% | 0 | 0 | — |
case-06 | pass→pass | 5,611 | 3,546 | -37% | 1 | 1 | 0% | 993 | 2,484 | +150% | 0 | 0 | — |
case-07 | pass→pass | 2,684 | 3,723 | +39% | 1 | 1 | 0% | 522 | 2,468 | +373% | 0 | 0 | — |
case-08 | pass→pass | 4,010 | 3,420 | -15% | 1 | 1 | 0% | 841 | 2,439 | +190% | 0 | 0 | — |
case-09 | pass→pass | 6,341 | 3,681 | -42% | 1 | 1 | 0% | 1,172 | 2,436 | +108% | 0 | 0 | — |
case-10 | pass→pass | 5,302 | 3,620 | -32% | 1 | 1 | 0% | 901 | 2,475 | +175% | 0 | 0 | — |
case-11 | pass→pass | 5,344 | 4,255 | -20% | 1 | 1 | 0% | 812 | 2,574 | +217% | 0 | 0 | — |
case-12 | fail→fail | 8,482 | 5,422 | -36% | 1 | 1 | 0% | 1,765 | 2,917 | +65% | 0 | 0 | — |
case-13 | fail→pass | 3,339 | 2,671 | -20% | 1 | 1 | 0% | 498 | 2,168 | +335% | 0 | 0 | — |
case-14 | pass→pass | 6,709 | 5,117 | -24% | 1 | 1 | 0% | 1,306 | 2,734 | +109% | 0 | 0 | — |
case-15 | pass→pass | 3,419 | 2,368 | -31% | 1 | 1 | 0% | 712 | 2,213 | +211% | 0 | 0 | — |
case-16 | fail→fail | 4,530 | 6,095 | +35% | 1 | 1 | 0% | 829 | 2,952 | +256% | 0 | 0 | — |
case-17 | pass→pass | 7,573 | 3,099 | -59% | 1 | 1 | 0% | 1,705 | 2,365 | +39% | 0 | 0 | — |
case-18 | pass→pass | 3,227 | 2,178 | -33% | 1 | 1 | 0% | 561 | 2,105 | +275% | 0 | 0 | — |
case-19 | fail→pass | 5,027 | 2,986 | -41% | 1 | 1 | 0% | 779 | 2,320 | +198% | 0 | 0 | — |
case-20 | pass→fail | 10,573 | 11,663 | +10% | 1 | 1 | 0% | 1,160 | 3,017 | +160% | 0 | 0 | — |
case-22 | pass→pass | 14,380 | 12,614 | -12% | 1 | 1 | 0% | 2,800 | 4,090 | +46% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of 0 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.