---
title: "Best Terraform agent skills to review Terraform plans: 5 compared (2026)"
canonical_url: https://cookiesforai.app/best/best-terraform-agent-skills
last_updated: 2026-10-02
type: article
summary: "terraform-test is the best Terraform agent skill for checking plans automatically and terraform-style-guide the best for reviewing HCL; none of HashiCorp's 20 skills reads terraform plan output for you (checked 2026-10-01)."
---

# Best Terraform agent skills for Claude Code, Codex and other agents

Updated 2026-10-02. First published 2026-10-01.

The best Terraform agent skill for checking plans is HashiCorp's terraform-test, which turns the checks a reviewer makes by eye into plan-mode tests that run on every pull request. For reviewing the HCL itself, pick terraform-style-guide, which ends in a ten-point review checklist. We compared 5 skills, four from HashiCorp's own repository and Anton Babenko's community terraform-skill, on fit to reviewing Terraform changes, how concrete the guidance is, which agents the publisher documents, and license. No skill we list reads `terraform plan` output for you; terraform-skill and an MCP server come closest, below. Facts checked on 2026-10-01 and 2026-10-02.

| Name | Best for | Made by | License | Notes | Checked |
|---|---|---|---|---|---|
| [Terraform test](https://cookiesforai.app/skills/hashicorp/terraform-test) | Checking plans automatically with plan-mode tests in CI | HashiCorp | MPL-2.0 | 881 stars | 2026-10-02 |
| [Terraform style guide](https://cookiesforai.app/skills/hashicorp/terraform-style-guide) | Reviewing Terraform code in a pull request | HashiCorp | MPL-2.0 | 881 stars | 2026-10-02 |
| [Refactor module](https://cookiesforai.app/skills/hashicorp/refactor-module) | Module refactors that must plan with no changes | HashiCorp | MPL-2.0 | 881 stars | 2026-10-02 |
| [Terraform policy](https://cookiesforai.app/skills/hashicorp/terraform-policy) | Turning review rules into Terraform Policy, or leaving Sentinel | HashiCorp | MPL-2.0 | 881 stars | 2026-10-02 |
| [Terraform skill](https://cookiesforai.app/skills/antonbabenko/terraform-skill) | A reviewed plan as a required gate before any production apply | Anton Babenko | Apache-2.0 | 2,394 stars | 2026-10-02 |

## terraform-test: the closest thing to automated plan review

terraform-test is HashiCorp's agent skill for writing and running Terraform's built-in tests, for teams that want plan checks repeated on every pull request instead of kept in a reviewer's head. Its strength for plan review is plan mode: a run block with `command = plan` creates nothing, and assert blocks then check resource counts, tags, conditional resources and outputs against what the plan would build. The skill names those files `*_unit_test.tftest.hcl` so CI can run them on every pull request, and a reference file gives ready GitHub Actions and GitLab CI pipelines. Its limit is that it checks only what you thought to assert: it does not read an existing plan and point out an unexpected destroy or replacement. Mock providers, which let tests run without cloud credentials, need Terraform 1.7.0 or newer. The skill folder was last changed on 2026-08-10. See [Terraform test](/skills/hashicorp/terraform-test).

## terraform-style-guide: a checklist for reviewing Terraform code

terraform-style-guide is HashiCorp's agent skill for writing and reviewing Terraform HCL to HashiCorp's published style conventions, for anyone who wants an agent's pull request reviews to apply the same rules every time. Its strength is a closing checklist of ten items: `terraform fmt` and `terraform validate` pass, files follow the standard split into terraform.tf, providers.tf, main.tf, variables.tf, outputs.tf and locals.tf, every variable has a type and description, versions are pinned, sensitive values are marked and no credentials are hardcoded. A SECURITY.md in the same folder covers encryption and keeping secrets out of state. Its limit is that it reviews code, not changes: it says nothing about which resources a plan will replace or destroy, and mentions `*.tfplan` files only as something never to commit. The folder was last changed on 2026-08-10, and hashicorp/agent-skills had 880 GitHub stars on 2026-10-01. See [Terraform style guide](/skills/hashicorp/terraform-style-guide).

## refactor-module: refactors that must plan with no changes

refactor-module is HashiCorp's agent skill for splitting a large Terraform configuration into reusable modules, for teams whose main.tf has grown a copied block per subnet or environment. It is the one HashiCorp skill here that makes the plan the pass mark: its success criteria include no resource recreation and no plan differences after the move, and it tells the agent to save the plan to a file, inspect it with `terraform show`, and apply only if it shows no changes. It writes `moved` blocks for Terraform 1.1 and newer, or `terraform state mv` commands for older versions, and lists addresses with `terraform state list` rather than printing state, which holds sensitive values in plain text. Its limit is scope: plan checking appears only as the last step of a refactor, not as a review of an arbitrary change. The folder was last changed on 2026-08-26. See [Refactor module](/skills/hashicorp/refactor-module).

## terraform-policy: review rules written down as policy

terraform-policy is HashiCorp's agent skill for Terraform Policy, the HCL policy language checked by the tfpolicy CLI, for teams that want a review rule such as "Block EC2 instances without encryption" enforced by policy rather than repeated in every review. Its strength is care about versions: before giving instructions the agent checks the installed tfpolicy version, because the skill keeps separate guidance for the 0.2.x and 0.3.x lines, which differ on points such as whether mock resources in .policytest.hcl files must declare attributes. It also converts single .sentinel policies and whole Sentinel libraries. Its limit is depth in the main file: the SKILL.md is a router of under 500 words that sends the agent to two reference guides, and nothing works without the tfpolicy CLI installed. It writes and tests policies; it does not review a plan. The folder was last changed on 2026-09-28, the most recent of the four HashiCorp skills. See [Terraform policy](/skills/hashicorp/terraform-policy).

## terraform-skill: a reviewed plan as a gate before any apply

terraform-skill is Anton Babenko's agent skill for writing, testing and reviewing Terraform and OpenTofu, for teams that want each agent answer to name its risk and a way back. Its strength for plan review is two fixed rules: the agent may not recommend a production apply without a reviewed plan artifact and an approval, and may not run a destroy before `terraform plan -destroy` has listed every resource it would delete. Each answer ends with the commands that validate the change, such as `terraform plan -out`, and how to roll back a change to state. Its limit is that it does not read a saved plan file for you: it shows how to export one with `terraform show -json` and leaves the reading to the agent and to you. It is a personal project, not HashiCorp's; its LICENSE file says Apache-2.0 while GitHub's license field shows NOASSERTION. The repository had 2,394 GitHub stars on 2026-10-02. See [Terraform skill](/skills/antonbabenko/terraform-skill).

## Is there an agent skill that reviews terraform plan output?

HashiCorp does not publish one. On 2026-10-01 hashicorp/agent-skills held 20 skills, 16 for Terraform and 4 for Packer, and none is built to read `terraform plan` output and report on it. In our [October 2026 field study](/research/ai-assistants-field-study-october-2026) we asked six AI assistants "Is there an agent skill that helps my coding agent review Terraform plans?" and the answers did not agree. ChatGPT gave three different first picks in three runs. Gemini named Anton Babenko's terraform-skill first in all three of its runs. Perplexity, Google AI Mode and Grok each gave a different mix of community skills, HashiCorp's skills and advice to write a custom SKILL.md.

A setup that works with the skills above today: save the plan with `terraform plan -out`, render it with `terraform show`, and ask the agent to review that output with terraform-style-guide loaded, the same commands refactor-module uses for its own check.

## A community Terraform skill we do not list yet

[LukasNiessen/terrashark](https://github.com/LukasNiessen/terrashark) had 718 stars on 2026-10-01, is MIT, and describes itself as a Terraform skill for Claude Code and Codex. Its SKILL.md, about 400 words, runs a failure-mode workflow (identity churn, secret exposure, blast radius, CI drift, compliance gaps) and also refuses a production apply without a reviewed plan and approval. Like terraform-skill, it makes a reviewed plan a gate inside a wider workflow rather than reading a saved plan file.

It is not in our table because it meets none of our [listing rules](/method): it is a personal project, it is below 5,000 stars, and in our runs on 2026-10-01 only one AI engine maker named it. terraform-skill is listed under the third rule, named by Google, xAI and Anthropic engines in most of their runs. The rules are about provenance, not a judgement of quality.

## The other route: HashiCorp's Terraform MCP server

The Terraform MCP server, [hashicorp/terraform-mcp-server](https://github.com/hashicorp/terraform-mcp-server), gives an agent tools instead of instructions; it had 1,539 GitHub stars on 2026-10-01 and is MPL-2.0. With an HCP Terraform or Terraform Enterprise token it exposes tools such as get_plan_details, get_plan_logs and get_plan_json_output, so an agent can fetch the plan of a real run and review it. The default toolset is registry lookups only, the run and plan tools need `TFE_TOKEN`, and tools that change things, such as action_run, also need `ENABLE_TF_OPERATIONS`. Plans run on a laptop or in plain CI are out of its reach. HashiCorp's README gives setup steps for VS Code, Cursor, Claude Code, Codex CLI, Gemini CLI, Claude Desktop, Amazon Q Developer, Kiro CLI and IBM Bob. We have not listed it in our MCP directory yet.

## How we compared

We read the SKILL.md and folder of each of the 4 HashiCorp skills on GitHub on 2026-10-01 and of terraform-skill on 2026-10-02, plus the file list of hashicorp/agent-skills, the SKILL.md of TerraShark, and the Terraform MCP server's README and tool registry. We ranked by four criteria in this order: fit to reviewing Terraform changes, how concrete the guidance is (commands, file names, pass criteria), which agents the publisher documents, and license terms. Stars and last-change dates come from the GitHub API on the same day. We did not run any skill on a real Terraform project, did not measure review quality, and did not connect the MCP server to HCP Terraform.

## How to choose

- If you want plan checks that run without a human, use terraform-test with `command = plan` runs, and add mock providers on Terraform 1.7.0 or newer so CI needs no cloud credentials.
- If you want an agent to review a Terraform pull request, load terraform-style-guide; when the change moves resources into modules, add refactor-module so the plan must show no changes.
- If your runs happen in HCP Terraform or Terraform Enterprise, connect the Terraform MCP server and let the agent fetch the plan JSON of the run under review.
- If your organization enforces rules with Sentinel today, use terraform-policy to move them to Terraform Policy.
- If you want a skill whose whole workflow treats a reviewed plan as a gate, use terraform-skill; TerraShark, which we do not list, takes the same approach.

## Questions people ask

### Is there an agent skill that reviews terraform plan output?

Not a dedicated one from HashiCorp: its 20 skills on 2026-10-01 include none for that job. terraform-test checks a plan against assertions you write, and the community skills antonbabenko/terraform-skill and TerraShark make a reviewed plan a required step before any production apply. If your runs live in HCP Terraform or Terraform Enterprise, HashiCorp's Terraform MCP server can fetch a run's plan as JSON for an agent to read.

### Do HashiCorp's Terraform agent skills work in Codex and Cursor?

Yes. HashiCorp's README documents GitHub Copilot, Claude Code, Codex, Cursor, OpenCode and IBM Bob. The skills CLI installs any single skill with npx skills add hashicorp/agent-skills --skill followed by its name, and Claude Code and Codex can also install HashiCorp's terraform plugin, which holds all 16 Terraform skills.

### Can I copy HashiCorp's Terraform skills into a private repository?

Yes. They are MPL-2.0, which allows use in closed source projects. Only if you change the skill files and distribute them must those changed files stay MPL-2.0 and be shared as source; your own Terraform code is not affected.


## Sources

- [hashicorp/agent-skills, list of all 20 SKILL.md files](https://github.com/hashicorp/agent-skills)
- [terraform-test SKILL.md](https://github.com/hashicorp/agent-skills/blob/main/plugins/terraform/skills/terraform-test/SKILL.md)
- [terraform-style-guide SKILL.md](https://github.com/hashicorp/agent-skills/blob/main/plugins/terraform/skills/terraform-style-guide/SKILL.md)
- [refactor-module SKILL.md](https://github.com/hashicorp/agent-skills/blob/main/plugins/terraform/skills/refactor-module/SKILL.md)
- [terraform-policy SKILL.md](https://github.com/hashicorp/agent-skills/blob/main/plugins/terraform/skills/terraform-policy/SKILL.md)
- [antonbabenko/terraform-skill SKILL.md and LICENSE](https://github.com/antonbabenko/terraform-skill)
- [LukasNiessen/terrashark SKILL.md](https://github.com/LukasNiessen/terrashark)
- [hashicorp/terraform-mcp-server README and tool registry](https://github.com/hashicorp/terraform-mcp-server)
