Infrastructure Code Review

VerifiedSafe

Comprehensive infrastructure review covering IaC, CI/CD, deployments, migrations, logging and observability using a specialized agent.

Sby Skills Guide Bot
DevOpsIntermediate
206/2/2026
Claude Code
#infrastructure-review#code-review#ci-cd#security#observability

Recommended for

Our review

Performs an in-depth infrastructure review by applying six checklists covering IaC, CI/CD, deployments, migrations, logging, and observability.

Strengths

  • Systematic application of multiple specialized checklists
  • Detection of security misconfigurations and operational risks
  • Assessment of production blast radius

Limitations

  • Requires infrastructure files to be modified in the working tree
  • Depends on the quality of the provided checklists
  • Can be slow for large changes
When to use it

When infrastructure changes (Terraform, CI/CD, migrations, etc.) are in the working tree and need a systematic review before deployment.

When not to use it

For purely application-level changes with no infrastructure or observability impact.

Security analysis

Safe
Quality score85/100

The skill instructs spawning a review agent with defined checklists; it does not execute any system commands or handle sensitive data unsafely.

No concerns found

Examples

Review infrastructure changes
Run an infrastructure-focused review using the senior-review-specialist agent. Apply all 6 checklists on the current working tree changes.
Check CI/CD pipeline safety
Review the CI/CD pipeline changes in the working tree for security misconfigurations and deployment risks.
Assess operational readiness
Perform an infrastructure review focusing on logging, alerting, and rollback capabilities for the current changes.

name: review:infra description: Infrastructure-focused review covering IaC, CI/CD, releases, migrations, logging, and observability. Spawns the senior-review-specialist agent for infrastructure analysis.

Infrastructure Code Review

Run an infrastructure-focused review using 6 infrastructure checklists via the senior-review-specialist agent.

Instructions

Spawn the senior-review-specialist agent to perform this review.

Checklists to Apply

Load and apply these review checklists:

  • commands/review/infra.md - Deployment config, least privilege, operational clarity
  • commands/review/ci.md - Pipeline security, deployment safety
  • commands/review/release.md - Versioning, rollout, migration, rollback
  • commands/review/migrations.md - Database migration safety
  • commands/review/logging.md - Secrets exposure, PII leaks, wide-events
  • commands/review/observability.md - Logs, metrics, tracing, alertability

Agent Instructions

The agent should:

  1. Get working tree changes: Run git diff to see all changes
  2. Identify infrastructure files:
    • Terraform, CloudFormation, Kubernetes manifests
    • CI/CD pipelines (GitHub Actions, GitLab CI, etc.)
    • Migration files, deployment scripts
    • Logging and monitoring configuration
  3. For each changed file:
    • Read the full file content
    • Go through each diff hunk
    • Apply all 6 infrastructure checklists
    • Look for security misconfigurations and operational risks
  4. Cross-reference related files: Check environment configs, secrets handling
  5. Assess blast radius: What could go wrong in production?

Output Format

Generate an infrastructure review report with:

  • Critical Issues (BLOCKER): Security misconfigurations, deployment risks
  • High Priority Issues: Missing guardrails, cost explosions
  • Medium Priority Issues: Observability gaps, operational hazards
  • Infrastructure Map: Components, dependencies, deployment topology
  • Operational Readiness: Logging, alerting, rollback capabilities
  • File Summary: Infrastructure issues per file
  • Overall Assessment: Production readiness recommendation
Related skills