terraform-policy

Terraform policy

terraform-policy is HashiCorp's agent skill for writing Terraform Policy files (.policy.hcl), testing them with .policytest.hcl, and converting Sentinel policies to the new format.

Install Terraform policy

Install this skill with the skills CLI

Terminal
npx skills add hashicorp/agent-skills --skill terraform-policy

Or, for Claude Code, add HashiCorp's plugin marketplace

Terminal
claude plugin marketplace add hashicorp/agent-skills

Then install the terraform plugin, which holds all 16 Terraform skills

Terminal
claude plugin install terraform@hashicorp

In Codex, HashiCorp's README says to add the repository's .agents/plugins/marketplace.json as a repository marketplace, then install the terraform plugin.

Or paste this into your coding agent: Install the agent skill terraform-policy from github.com/hashicorp/agent-skills. A skill can include scripts that run on your computer, so read its source first.

What Terraform policy does

terraform-policy is an agent skill from HashiCorp for Terraform Policy, the HCL-based policy language checked by the tfpolicy CLI. It handles four jobs: writing a new .policy.hcl policy from a requirement such as blocking unencrypted EC2 volumes, converting a .sentinel policy, writing or fixing a .policytest.hcl test, and migrating a whole Sentinel policy library.

The terraform-policy skill is a router. Its SKILL.md is short and sends the agent to one of two reference guides: one for authoring and converting policies, one for writing tests. Before giving any instructions, the agent checks the installed tfpolicy version, because the skill keeps guidance for the 0.2.x and 0.3.x lines and their rules differ, for example on whether mock resources in tests must declare attributes.

The skill also lists features that only exist in newer versions, such as the core::alltrue and core::anytrue functions and schema checks that run before any test in 0.3.x. If the version is unknown, the agent is told to ask or to give guidance that keeps the two paths apart. A README and example policies sit in the same folder.

When to use Terraform policy

  • You are moving from Sentinel to Terraform Policy and want policies converted.
  • You need a new policy, such as requiring encryption on every storage volume.
  • A .policytest.hcl test fails and you want help finding out why.
  • You want tests written for an existing .policy.hcl file.

When to pick something else

  • Reviewing the output of terraform plan before an apply: HashiCorp's 20 skills (read 2026-10-01) include none made only for that job.
  • Testing Terraform modules (.tftest.hcl): use terraform-test from the same repository.

What Terraform policy needs

  • The tfpolicy CLI, version 0.2.x or 0.3.x

Which agents Terraform policy works in

HashiCorp documents Terraform policy for GitHub Copilot, Claude Code, Codex, Cursor, OpenCode, IBM Bob. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.

Terraform policy license

Terraform policy is published under MPL-2.0. MPL-2.0 is a file-level copyleft license: you can use and copy the skill in any project, including closed source ones, but if you distribute changed versions of its files, those files stay under MPL-2.0 and must be shared as source.

Questions people ask

Does HashiCorp have an agent skill that reviews terraform plan output?

No. On 2026-10-01 hashicorp/agent-skills held 20 skills, 16 for Terraform and 4 for Packer, and none is dedicated to reading or reviewing terraform plan output. The closest is terraform-test, which can run tests in plan mode against assertions you write.

Can I copy this HashiCorp skill into my own repository?

Yes. The skill is MPL-2.0. You can copy and use it in any project, open or closed source. If you change its files and distribute them, the changed files must stay MPL-2.0 and be available as source; your own files are not affected.

  • Terraform skill: terraform-skill is Anton Babenko's agent skill for writing, testing and reviewing Terraform and OpenTofu, which names the risk before it writes code and never recommends a production apply without a reviewed plan. (2,394 repository stars on October 2, 2026)
  • Refactor module: refactor-module is HashiCorp's agent skill for turning a monolithic Terraform configuration into reusable modules, with typed interfaces, documentation, tests and a state migration that recreates no resources. (881 repository stars on October 2, 2026)
  • Terraform style guide: terraform-style-guide is HashiCorp's agent skill for writing and reviewing Terraform HCL to the official style conventions: file layout, formatting, naming, typed variables, version pinning and a review checklist. (881 repository stars on October 2, 2026)
  • Terraform test: terraform-test is HashiCorp's agent skill for writing and running Terraform's built-in tests: .tftest.hcl files with run blocks, assertions, expected failures, mock providers and CI pipelines. (881 repository stars on October 2, 2026)

Lists that include terraform-policy