Terraform Security Misconfiguration Detection
Given Terraform snippets and a security ruleset, identify overly broad IAM permissions, public storage, exposed networking, and missing encryption with resource locations.
View token rates · observed 9/11/2026
Compare 2 router rates · observed 9/11/2026
Compare 2 router rates · observed 9/11/2026
All 12 model results and methodology
Generated 100/100 examples
| Model | Tier | Quality | Judged | Scenario cost |
|---|---|---|---|---|
| Nemotron Nano 9B v2 | small | 53% | 100/100 | $42.55 |
| Qwen3 235B A22B | mid | 81% | 100/100 | $289 |
| DeepSeek V3 | mid | 82% | 100/100 | $118 |
| Mistral Large 2407 | mid | 82% | 100/100 | $229 |
| Arcee Trinity Large Thinking | mid | 46% | 100/100 | $150 |
| GPT-5.4 | frontier | 97% | 100/100 | $2344 |
| Claude Opus 4.7 | frontier | 25% | 100/100 | $5581 |
| Gemini 3.1 Pro Preview | frontier | 11% | 100/100 | $2548 |
| Gemma 4 E4B IT | small | 63% | 100/100 | $13.59 |
| Granite 4.1 8B | small | 40% | 100/100 | $13.96 |
| Ministral 8B Instruct 2410 | small | 33% | 100/100 | $24.63 |
| Qwen3 4B Instruct 2507 | small | 45% | 100/100 | $122 |
LLM-judge pass rate on 100 synthetic examples. Generator: gpt-5.2. Judge: gpt-5.2. Evaluated 2026-09-10T08:57:54.110Z.
Directional: measured on a synthetic eval set generated by drydock. Cost/latency are not yet captured for taskrouter-run benchmarks.
drydock