trivy-config
testland/qaRuns Trivy's misconfiguration scanner (`trivy config`) against IaC directories to detect security issues across Terraform, CloudFormation, Kubernetes…
Scores out of 100 · grade B+
2026-08-20Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score11/100
- 5 stars on the source repo.
Documented
15% of the score90/100
- 1,281 words with worked examples.
- Ships 4 bundled files.
Install
npx skills add testland/qa/trivy-configWhat it says it does
Runs Trivy's misconfiguration scanner (`trivy config`) against IaC directories to detect security issues across Terraform, CloudFormation, Kubernetes manifests, Helm charts, Dockerfiles, and Azure ARM templates - installs Trivy, scans with severity gating via `--exit-code`, suppresses findings via `.trivyignore` / `.trivyignore.yaml` or inline annotations, extends built-in checks with custom Rego policies, and emits SARIF for GitHub Code Scanning. Trivy is the tfsec successor - the forward path from tfsec per Aqua Security's own migration guidance - and the legacy tfsec workflow (install, custom YAML rules, ignore annotations, migration steps) is kept in references/tfsec-legacy.md. Use when adopting a consolidated IaC scanner for new projects, migrating away from tfsec (or still operating a Terraform-only tfsec stack), or scanning mixed IaC stacks with a single tool.
Also in testland/qa
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| idempotency-test-authortestland/qa | clean | Skill | 5 stars | yesterday | |
| flaky-test-quarantinetestland/qa | clean | Skill | 5 stars | yesterday | |
| appium-testingtestland/qa | clean | Skill | 5 stars | yesterday | |
| fast-check-testingtestland/qa | clean | Skill | 5 stars | yesterday | |
| negative-test-generatortestland/qa | clean | Skill | 5 stars | yesterday | |
| test-code-conventionstestland/qa | clean | Skill | 5 stars | yesterday |
Other devops & infra skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| deploy-to-vercelvercel-labs/agent-skills | No license | DevOps & infra | 111,601 installs | today | |
| azure-quotasmicrosoft/azure-skills | clean | DevOps & infra | 406,483 installs | today | |
| vercel-cli-with-tokensvercel-labs/agent-skills | No license | DevOps & infra | 84,971 installs | today | |
| azure-reliabilitymicrosoft/azure-skills | clean | DevOps & infra | 218,648 installs | today | |
| azure-validatemicrosoft/azure-skills | clean | DevOps & infra | 537,848 installs | today | |
| agent-platform-deploygoogle/skills | clean | DevOps & infra | 4,797 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=testland%2Fqa)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
