The problem

IAM wildcards and public S3 buckets keep slipping through

Terraform code review. Tools like Checkov and tfsec exist

but they live in CI, require config files, and developers

ignore the output because it's not where they're working.