---
title: "terraform-skill: write, test and review Terraform and OpenTofu"
canonical_url: https://cookiesforai.app/skills/antonbabenko/terraform-skill
last_updated: 2026-10-02T03:01:13+02:00
type: skill
summary: "terraform-skill is Anton Babenko's agent skill for writing, testing and reviewing Terraform and OpenTofu, which names the risk before it writes code and never recommends a production apply without a reviewed plan."
install: "npx skills add antonbabenko/terraform-skill --skill terraform-skill"
related:
  - "https://cookiesforai.app/skills/hashicorp/refactor-module"
  - "https://cookiesforai.app/skills/hashicorp/terraform-policy"
  - "https://cookiesforai.app/skills/hashicorp/terraform-style-guide"
  - "https://cookiesforai.app/skills/hashicorp/terraform-test"
---

# Terraform skill

terraform-skill is Anton Babenko's agent skill for writing, testing and reviewing Terraform and OpenTofu, which names the risk before it writes code and never recommends a production apply without a reviewed plan.

| Fact | Value |
|---|---|
| Publisher | Anton Babenko |
| Source | https://github.com/antonbabenko/terraform-skill/tree/HEAD/skills/terraform-skill |
| License | Apache-2.0 |
| Repository stars | 2,394 on 2026-10-02 |
| Skill name | terraform-skill |
| Version | 1.17.1 (from its SKILL.md, https://github.com/antonbabenko/terraform-skill/blob/HEAD/skills/terraform-skill/SKILL.md, read 2026-10-02) |
| Category | Infrastructure as code |
| Skill last changed | 2026-06-03 |
| Page updated | 2026-10-02 |
| Facts checked | 2026-10-02 |

## Install

Install this skill with the skills CLI:

```
npx skills add antonbabenko/terraform-skill --skill terraform-skill
```

Or, in Claude Code, add Anton Babenko's plugin marketplace:

```
/plugin marketplace add antonbabenko/agent-plugins
```

Then install the terraform-skill plugin:

```
/plugin install terraform-skill@antonbabenko
```

Or, in Gemini CLI, install it as an extension:

```
gemini extensions install https://github.com/antonbabenko/terraform-skill
```

For Cursor, Codex, OpenCode, Kiro and other agents, the README gives a git clone into each agent's skills folder.

## Ask your coding agent

A skill can include scripts that run on your computer, so read its source first: https://github.com/antonbabenko/terraform-skill/tree/HEAD/skills/terraform-skill

```text
Install the agent skill terraform-skill from github.com/antonbabenko/terraform-skill.
```

## What it does

terraform-skill is an agent skill by Anton Babenko that makes an agent diagnose a Terraform or OpenTofu task before it writes code. The agent first records the runtime and version, the providers, the state backend, where the code runs and how critical the environment is. It then names the failure category, such as identity churn after a refactor, secrets leaking into state, an oversized blast radius, CI drift or state corruption, and loads only the reference file for that category.

Every answer under terraform-skill ends with the same five parts: assumptions and version floor, the risk addressed, the fix and its tradeoffs, the exact commands that validate it (fmt -check, validate, plan -out, a policy check), and how to roll back a change to state. Two rules matter most for reviews: no production apply is recommended without a reviewed plan artifact and an approval, and no destroy runs before terraform plan -destroy has listed every resource it would delete.

terraform-skill also bundles eight reference files the agent reads only when a task needs them: native terraform test versus Terratest, why computed values need command = apply in tests, module layout and variable contracts, S3 native state locking from Terraform 1.10, write_only arguments from 1.11 to keep secrets out of state, and CI templates for GitHub Actions, GitLab CI and Atlantis. Examples default to AWS; the README says Azure and GCP are covered too.

## When to use it

- You want your agent to review a Terraform or OpenTofu change and refuse a production apply without a saved, reviewed plan.
- You are about to run a targeted destroy and want every resource it would delete listed first.
- You are choosing between native terraform test and Terratest, or adding mock providers so CI needs no cloud credentials.
- You want a CI pipeline that applies exactly the plan someone reviewed instead of planning again.

## When to pick something else

- A ready-made report on a saved plan file: terraform-skill makes a reviewed plan a gate and shows how to export a plan with terraform show -json, but reading the plan is left to the agent and to you.
- Writing Terraform Policy or moving Sentinel policies: HashiCorp's terraform-policy skill is built for that.

## What it needs

- Terraform 1.0 or newer, or OpenTofu 1.6 or newer; native tests need 1.6 and mock providers 1.7
- Optional: HashiCorp's Terraform MCP server for registry lookups, and the terraform-ls language server

## Which agents it works in

Anton Babenko documents it for Claude Code, Cursor, GitHub Copilot, Gemini CLI, OpenCode, Codex, Kiro, Antigravity, Autohand Code. The open skills CLI also installs it into 78 agents (listed with the CLI on 2026-10-02).

## License

Apache-2.0. Apache-2.0 lets you use, change and share the skill in any project, including closed source ones, if you keep its license and notices. GitHub shows NOASSERTION because it could not match the LICENSE file, which opens with a copyright line and two lines naming websites before the full Apache License 2.0 text; the SKILL.md frontmatter also says Apache-2.0.

## Questions people ask

### Does terraform-skill review terraform plan output?

Partly. It does not read a saved plan file for you, but it forbids recommending a production apply without a reviewed plan artifact and an approval, and requires terraform plan -destroy with every deleted resource listed before any destroy. In CI it applies the reviewed plan from the plan stage instead of planning again.

### Is terraform-skill from HashiCorp?

No. It is Anton Babenko's own project. HashiCorp publishes its skills in hashicorp/agent-skills, which held 16 Terraform skills on 2026-10-01; none of them is built mainly for plan review either.

## Related

### Related skills for infrastructure as code

- [Refactor module](https://cookiesforai.app/skills/hashicorp/refactor-module): refactor-module is HashiCorp's agent skill for turning a monolithic Terraform configuration into reusable modules, with typed interfaces, documentation, tests and a state migration that recreates no resources.
- [Terraform policy](https://cookiesforai.app/skills/hashicorp/terraform-policy): terraform-policy is HashiCorp's agent skill for writing Terraform Policy files (.policy.hcl), testing them with .policytest.hcl, and converting Sentinel policies to the new format.
- [Terraform style guide](https://cookiesforai.app/skills/hashicorp/terraform-style-guide): terraform-style-guide is HashiCorp's agent skill for writing and reviewing Terraform HCL to the official style conventions: file layout, formatting, naming, typed variables, version pinning and a review checklist.
- [Terraform test](https://cookiesforai.app/skills/hashicorp/terraform-test): terraform-test is HashiCorp's agent skill for writing and running Terraform's built-in tests: .tftest.hcl files with run blocks, assertions, expected failures, mock providers and CI pipelines.

