terraform-skill

Terraform skill

terraform-skill is Anton Babenko's agent skill for writing, testing and reviewing Terraform and OpenTofu, which names the risk before it writes code and never recommends a production apply without a reviewed plan.

Install Terraform skill

Install this skill with the skills CLI

Terminal
npx skills add antonbabenko/terraform-skill --skill terraform-skill

Or, in Claude Code, add Anton Babenko's plugin marketplace

Terminal
/plugin marketplace add antonbabenko/agent-plugins

Then install the terraform-skill plugin

Terminal
/plugin install terraform-skill@antonbabenko

Or, in Gemini CLI, install it as an extension

Terminal
gemini extensions install https://github.com/antonbabenko/terraform-skill

For Cursor, Codex, OpenCode, Kiro and other agents, the README gives a git clone into each agent's skills folder.

Or paste this into your coding agent: Install the agent skill terraform-skill from github.com/antonbabenko/terraform-skill. A skill can include scripts that run on your computer, so read its source first.

What Terraform skill does

terraform-skill is an agent skill by Anton Babenko that makes an agent diagnose a Terraform or OpenTofu task before it writes code. The agent first records the runtime and version, the providers, the state backend, where the code runs and how critical the environment is. It then names the failure category, such as identity churn after a refactor, secrets leaking into state, an oversized blast radius, CI drift or state corruption, and loads only the reference file for that category.

Every answer under terraform-skill ends with the same five parts: assumptions and version floor, the risk addressed, the fix and its tradeoffs, the exact commands that validate it (fmt -check, validate, plan -out, a policy check), and how to roll back a change to state. Two rules matter most for reviews: no production apply is recommended without a reviewed plan artifact and an approval, and no destroy runs before terraform plan -destroy has listed every resource it would delete.

terraform-skill also bundles eight reference files the agent reads only when a task needs them: native terraform test versus Terratest, why computed values need command = apply in tests, module layout and variable contracts, S3 native state locking from Terraform 1.10, write_only arguments from 1.11 to keep secrets out of state, and CI templates for GitHub Actions, GitLab CI and Atlantis. Examples default to AWS; the README says Azure and GCP are covered too.

When to use Terraform skill

  • You want your agent to review a Terraform or OpenTofu change and refuse a production apply without a saved, reviewed plan.
  • You are about to run a targeted destroy and want every resource it would delete listed first.
  • You are choosing between native terraform test and Terratest, or adding mock providers so CI needs no cloud credentials.
  • You want a CI pipeline that applies exactly the plan someone reviewed instead of planning again.

When to pick something else

  • A ready-made report on a saved plan file: terraform-skill makes a reviewed plan a gate and shows how to export a plan with terraform show -json, but reading the plan is left to the agent and to you.
  • Writing Terraform Policy or moving Sentinel policies: HashiCorp's terraform-policy skill is built for that.

What Terraform skill needs

  • Terraform 1.0 or newer, or OpenTofu 1.6 or newer; native tests need 1.6 and mock providers 1.7
  • Optional: HashiCorp's Terraform MCP server for registry lookups, and the terraform-ls language server

Which agents Terraform skill works in

Anton Babenko documents Terraform skill for Claude Code, Cursor, GitHub Copilot, Gemini CLI, OpenCode, Codex, Kiro, Antigravity, Autohand Code. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 2, 2026). See where each agent looks for skills.

Terraform skill license

Terraform skill is published under Apache-2.0. Apache-2.0 lets you use, change and share the skill in any project, including closed source ones, if you keep its license and notices. GitHub shows NOASSERTION because it could not match the LICENSE file, which opens with a copyright line and two lines naming websites before the full Apache License 2.0 text; the SKILL.md frontmatter also says Apache-2.0.

Questions people ask

Does terraform-skill review terraform plan output?

Partly. It does not read a saved plan file for you, but it forbids recommending a production apply without a reviewed plan artifact and an approval, and requires terraform plan -destroy with every deleted resource listed before any destroy. In CI it applies the reviewed plan from the plan stage instead of planning again.

Is terraform-skill from HashiCorp?

No. It is Anton Babenko's own project. HashiCorp publishes its skills in hashicorp/agent-skills, which held 16 Terraform skills on 2026-10-01; none of them is built mainly for plan review either.

  • Refactor module: refactor-module is HashiCorp's agent skill for turning a monolithic Terraform configuration into reusable modules, with typed interfaces, documentation, tests and a state migration that recreates no resources. (881 repository stars on October 2, 2026)
  • Terraform policy: terraform-policy is HashiCorp's agent skill for writing Terraform Policy files (.policy.hcl), testing them with .policytest.hcl, and converting Sentinel policies to the new format. (881 repository stars on October 2, 2026)
  • Terraform style guide: terraform-style-guide is HashiCorp's agent skill for writing and reviewing Terraform HCL to the official style conventions: file layout, formatting, naming, typed variables, version pinning and a review checklist. (881 repository stars on October 2, 2026)
  • Terraform test: terraform-test is HashiCorp's agent skill for writing and running Terraform's built-in tests: .tftest.hcl files with run blocks, assertions, expected failures, mock providers and CI pipelines. (881 repository stars on October 2, 2026)

Lists that include terraform-skill