terraview for
<h2>terraview: AI-assisted Terraform security scanning in a single binary</h2>
- Free
- 4.6
- V v0.10.0
<h2>terraview: AI-assisted Terraform security scanning in a single binary</h2>
terraview, created by Leonamvasquez, is a security analysis tool for Terraform infrastructure-as-code that automates pre-deployment audits. Distributed as a single binary with no external dependencies, the tool combines multiple static scanners with optional AI-based contextual analysis to flag misconfigurations, compliance gaps, and maintainability concerns inside Terraform plans. It produces machine-readable reports and simple visual maps. DevOps engineers and cloud security teams get consolidated findings and actionable remediation guidance before CI/CD runs.
What tasks can you actually use it for?
Terraview functions as a wrapper and orchestrator that runs established Terraform scanners and adds contextual interpretation, making it suitable for pre-deployment security reviews and policy enforcement. It aggregates scan outputs, assigns a built-in security score across security, compliance, and maintainability, and generates ASCII-based diagrams to visualise resources. Outputs include machine-readable reports and remediation suggestions, which teams can feed into code review or build-gating workflows.
How reliable are its findings for Terraform plans?
The tool bases its flagged issues on three industry scanners, Checkov, tfsec, and Terrascan, so static findings reflect those projects' detection logic. The AI-enhanced contextual analysis generates remediation proposals using large language models, and the security scoring system quantifies infrastructure health. Users should treat generated fixes as recommendations and validate them, because the AI analysis builds on model patterns rather than authoritative policy enforcement.
What file formats, inputs, and integrations does it accept?
Terraview requires Terraform to be installed on the host and accepts standard Terraform plans as input. It supports JSON and Markdown report exports for CI/CD parsing and a policy-as-code mechanism for custom rules. The app acts as an MCP server, enabling programmatic calls from AI agents and IDEs, and supports multiple AI providers when AI features are enabled, allowing teams to select their preferred model endpoint.
Does it fit into CI/CD pipelines and team workflows?
The single-binary distribution with no external dependencies simplifies deployment into build agents and developer machines. Parallel execution runs scanners and AI tasks simultaneously to reduce scan time, and JSON output integrates with automation to fail builds based on thresholds. AI-driven analysis requires an API key only when enabled, so core static scanning can run without external model calls, giving teams control over when to involve third-party services.
A pragmatic option for teams that favour community-backed IaC tooling
Terraview is a practical choice for teams that prefer open-source, community-supported tools, given its positive reception in the open-source and DevOps communities. Expect to run a short evaluation to confirm the tool's AI suggestions align with your internal standards and risk tolerance. Use the app as an assistive reviewer alongside existing review processes rather than as a wholesale replacement for human policy checks.
Pros
- Aggregates Checkov, tfsec, and Terrascan into one report
- Provides AI-driven remediation suggestions using LLMs
- Distributed as a single binary with no external dependencies
- Exports JSON and Markdown for pipeline integration
Cons
- AI features require an external API key and provider access
- Generated remediation proposals need human validation for sensitive changes
- Requires Terraform installed on the host system
- ASCII diagrams are basic for complex architectures
terraview for
- Free
- 4.6
- V v0.10.0
Top downloads
passwd-page
passwd-page: zero-knowledge secret sharing for AI agents
tinybrain
Secure MCP sandbox for local execution of model-generated code
mcp-wallfacer
mcp-wallfacer: an MCP server to monitor and block prompt attacks
pyobfus
pyobfus: MCP-native Python obfuscation for AI-assisted workflows
mcp-aguara
Protocol-native security gateway for MCP agents and LLMs
Discover more programs
waftester
- 4.9
- Free
mcp-reticle
- 4.9
- Free
Real-time MCP JSON-RPC proxy and visual debugger for agents
minibridge
- 4.9
- Free
minibridge: Securely expose MCP servers using SSE and TLS
dcert
- 4
- Free
dcert: MCP-native TLS certificate manager for automated workflows
aguara
- 4.7
- Free
cloudsword
- 4.9
- Free
Comprehensive Tool for Cloud Security Assessment
MCP-Defender
- 4.9
- Free
authprobe
- 4.7
- Free
authprobe CLI for diagnosing MCP OAuth authentication failures
agent-audit
- 4.7
- Free
Static security scanner for MCP agents and agentic workflows
trivy-mcp
- 4.6
- Free
Efficient AI Security Plugin for Developers
Mcp Ethical Hacking
- 4.9
- Free
Mcp Ethical Hacking: MCP-focused toolkit for security research and education
wassette
- 4.9
- Free
Wassette: A Runtime for WebAssembly Components