TL;DR: This open-source project runs checks across AWS/GCP/Azure with YAML rules and tiny runtime. I spun it up locally and was able to run my first scans in ~5 minutes and identify orphan resources. If you need auditable infra rules that don't require a heavyweight agent, this is worth a try.
Repo:
https://github.com/kexa-io/Kexa