Integration · Security scanning
Checkov + OrchestrAI
Catalog exported 2026-09-02 · Checkov website
Scan Terraform and other IaC files or plan output with Checkov from chat and read the findings in place.
OrchestrAI exposes 5 Checkov operations: 5 are low-risk (read-only or low-impact).
What teams use it for
Security-minded teams run Checkov through OrchestrAI on a module directory, a single file, or a Terraform plan JSON before they confirm an apply, then read the failing checks in the same conversation. Listing available checks and fetching a previous report help when deciding which policies to suppress. Checkov scans are low risk and need no stored credentials. There is no operation to auto-fix findings or write suppression comments, so remediation edits are yours to make.
Every Checkov operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Checkov Get Report |
Get Checkov scan report | Low risk | No |
Checkov List Checks |
List available Checkov checks | Low risk | No |
Checkov Scan Directory |
Scan IaC directory for security issues | Low risk | No |
Checkov Scan File |
Scan single IaC file for security issues | Low risk | No |
Checkov Scan Terraform Plan |
Scan Terraform plan JSON file | Low risk | No |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
What you connect
No Checkov-specific credential; these operations run against your connected cloud account. Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.
Prompts that work
- Run Checkov on the infra/modules/vpc directory and summarize the failed checks by severity
- Scan the tfplan.json I just generated for the prod workspace and flag anything about public S3 buckets
- List the Checkov checks that cover AWS IAM so I know which ones to enable
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Does OrchestrAI need credentials to run Checkov?
- No. Checkov operates on local files and plan output, and none of the five Checkov operations require a stored credential.
- Can OrchestrAI fix Checkov findings automatically?
- No. The available operations scan directories, files, and plan JSON and return reports. Fixing the configuration is a separate manual step.
- How does OrchestrAI authenticate to Checkov?
- You add a Checkov credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.