The question worth asking about a Terraform change is not "is this correct". It is "what does this destroy, and what does it expose".
My review prompt:
"Here is a terraform plan output. Answer only these:
1. Which resources are destroyed or replaced, and is any of them stateful?
1. Which change alters a security group, IAM policy, or public accessibility, and in which direction?
1. Which change causes downtime, and how long?
1. What is missing that this change implies — an alarm, a backup, a DNS record?
Do not comment on style."
Question 4 is the one that has caught real problems for me: a new RDS instance with no backup retention, a new ALB with no alarm on 5xx. The plan is correct, the change is incomplete, and only the fourth question finds it.