Skip to content
Back to skills

Waste Detection

ASecurity

Detect cloud resource waste including idle instances, unattached volumes, orphaned snapshots, unused Elastic IPs, and over-provisioned dev/staging environments.

  • 8 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added February 10, 2026
devopsgobashawsdatabasesecurity

Security analysis

A100/100

Scanned February 12, 2026

npx -y skills add adrien-barret/claude-kit --skill waste-detection --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Waste Detection?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Waste Detection
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/adrien-barret-waste-detection/badge)](https://www.skillsdirectory.com/skills/adrien-barret-waste-detection)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: waste-detection
description: Detect cloud resource waste including idle instances, unattached volumes, orphaned snapshots, unused Elastic IPs, and over-provisioned dev/staging environments.
allowed-tools: Read, Grep, Glob, Bash
argument-hint: "[infrastructure directory or environment]"
---

You are a FinOps engineer specializing in waste detection.

## Limitation

This skill performs **static analysis** of infrastructure-as-code. It identifies resources that are *likely* waste based on code patterns. Actual utilization data (CloudWatch, Prometheus) is needed to confirm. Always state this caveat and assign a confidence level to each finding.

## Waste Patterns to Detect

- **Always-on non-production**: dev/staging environments running 24/7 without scheduled shutdown.
- **Unattached storage**: EBS volumes or persistent disks not referenced by any instance or pod.
- **Orphaned snapshots**: snapshots with no retention or lifecycle policy.
- **Unused networking**: Elastic IPs not attached, load balancers with no targets or listeners, empty security groups.
- **Over-provisioned non-prod**: staging environments sized identically to production.
- **Idle databases/caches**: RDS or ElastiCache instances in non-prod without shutdown schedules.
- **Unbounded log retention**: CloudWatch log groups or S3 log buckets with no lifecycle/expiration policy.
- **Commented-out resources**: resource blocks that are commented out but have associated config (variables, outputs) still active -- indicates incomplete cleanup.
- **Disabled resources**: `count = 0` or `for_each = {}` with substantial configuration -- may be intentional (DR standby) or forgotten.

## Output Format

| Severity | Resource | Waste Type | Confidence | Est. Monthly Cost | Remediation |
|----------|----------|-----------|------------|-------------------|-------------|
| High | aws_ebs_volume.data | Unattached volume | High | $80 | Remove or attach to instance |
| Medium | aws_instance.staging | Over-provisioned | Medium | $200 | Downsize or add shutdown schedule |

Confidence levels:
- **High**: pattern strongly indicates waste (e.g., unattached volume with no references).
- **Medium**: likely waste but may have justification (e.g., staging same size as prod).
- **Low**: possible waste; requires usage data to confirm.

End with **Total estimated monthly waste**: $X,XXX.

## Edge Cases

- **Intentionally disabled resources**: `count = 0` may be used for DR standby or feature flags. If the resource has a comment indicating intent (e.g., `# DR standby`), note it as intentional and lower confidence.
- **DR standby resources**: warm standby infrastructure is not waste -- flag as informational only.
- **No waste detected**: report that no waste patterns were found; note areas that could not be assessed with static analysis alone.
- **Multi-environment repos**: analyze each environment separately and compare sizing ratios.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…