Understand consequences

Lenses and coverage

Evaluate different consequences over the same infrastructure model, with explicit bounds on every conclusion.

Security and reachability

The native engine evaluates findings and graph relationships, including internet-reachable resources and privilege-escalation signals. Attack paths and blast radius help explain effects beyond a single changed resource.

These are graph-based predictions. They are not live exploit execution or a complete evaluation of every IAM and network policy.

Configuration checks

The engine can serialize supported infrastructure and run Checkov as an additional configuration lens. A combined verdict compares before and after findings.

Inspect scanner_available. The scanner is optional, and incomplete serialization or an unavailable executable limits coverage.

Provisioned-cost estimates

The current engine uses a small curated pricing table with a stated region and monthly-hour assumption. It reports known provisioned charges and identifies unknown prices or usage-based costs.

A live AWS Price List integration is a roadmap direction. Current values are estimates, not your AWS bill. RDS or other unsupported prices must not be invented.

Cost basisInterpretation
provisioned-estimateA supported resource with a known table price
usage-based-unknownRequires actual usage information
price-unavailableNo supported price for the resource

Availability and recovery

Native rules and category scores include infrastructure configuration signals for availability and disaster recovery. These do not predict uptime, failover timing, or whether an application can serve a particular load.

What needs a real run

Application latency, throughput, runtime correctness, recovery time, and usage-based spend require execution or measured telemetry. Emfirge’s model does not produce those measurements.

Based on the Emfirge MCP and engine source.View source
Documentation