# antonbabenko/terraform-skill: Terraform and OpenTofu Rules for AI Coding Agents

> A skill package that gives Claude Code, Cursor, Copilot, Codex and other agents opinionated Terraform and OpenTofu guidance on testing, modules, state and CI/CD. Useful if your agent already writes Terraform badly; not a substitute for knowing Terraform yourself.

**antonbabenko/terraform-skill** — Terraform & OpenTofu Skill for AI Agents - testing, modules, CI/CD, and production patterns

- Repository: https://github.com/antonbabenko/terraform-skill
- Stars: 2,392 · Forks: 217
- Language: Unknown
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/antonbabenko-terraform-skill

## The gap this fills: agents that write plausible but non-idiomatic Terraform

General-purpose coding agents are good at producing Terraform that parses and bad at producing Terraform that a platform team would accept. They invent module layouts, skip tests, and default to whatever backend pattern appeared most often in training data. antonbabenko/terraform-skill is a packaged set of rules that an agent loads before it answers, covering testing frameworks, module development, state management, CI/CD integration, security and compliance, and quick-reference decision flowcharts. The README describes the intent plainly: it helps the agent test code, structure modules, set up CI/CD, and write production infrastructure code.

The target reader is not someone learning Terraform. It is a team that already has an agent in the loop and wants the agent's output to match house conventions. The README states that AWS, Azure and GCP are all first-class, with AWS as the default in examples, and that asking for the Azure or GCP equivalent of a pattern maps to that provider. That claim matters because most Terraform guidance in the wild is AWS-shaped by accident rather than by design.

## How the skill reaches the agent: SKILL.md, per-host discovery paths, and a Kiro power

The mechanism is file-based, not a service. The repository ships a skills/terraform-skill directory containing SKILL.md, and each supported host discovers that file from a path it already watches. Cursor reads .agents/skills/ and .cursor/skills/. Copilot reads .copilot/skills/. OpenCode reads .agents/skills/, .opencode/skills/ and .claude/skills/. Codex reads ~/.agents/skills/ and .agents/skills/. Kiro reads .kiro/skills/ and ~/.kiro/skills/. Autohand Code reads ~/.autohand/skills/ and .autohand/skills/. There is no daemon and no network call at answer time.

The Kiro path is different and worth understanding before you install. The repository is also a Kiro Power, with a root POWER.md and an optional mcp.json. The README says POWER.md is generated from skills/terraform-skill/SKILL.md, so the skill content is shared rather than duplicated. Kiro activates the power on keyword match, for example "terraform", "opentofu", "state" or "modules". Installing it also registers the optional read-only HashiCorp terraform-mcp-server from mcp.json under the Powers section of ~/.kiro/settings/mcp.json. The README is explicit that the guidance works without that server, which is the right default: a read-only MCP server is a convenience, and you should decide separately whether you want your agent talking to a Terraform MCP endpoint at all.

## Installing terraform-skill and running a first real prompt

The fastest path works with any Agent Skills-compatible tool. The README gives this as the quick install:

```bash
npx skills add https://github.com/antonbabenko/terraform-skill
```

For Claude Code the README uses the plugin marketplace instead. Note the warning attached to it: terraform-skill is listed in antonbabenko/agent-plugins as an external plugin, and the README says not to also add antonbabenko/terraform-skill as a marketplace, because both use the same marketplace name and will clash.

```bash
/plugin marketplace add antonbabenko/agent-plugins
/plugin install terraform-skill@antonbabenko
```

If you prefer a local clone you control, the manual route symlinks the checkout into the Claude plugins directory. The README notes that Claude Code autodiscovers the skill at skills/terraform-skill/SKILL.md on next launch, and that edits to the clone are picked up live. That live-edit behaviour is the reason to prefer this route if you intend to fork and adjust the guidance.

```bash
git clone https://github.com/antonbabenko/terraform-skill
mkdir -p ~/.claude/plugins
ln -s "$(pwd)/terraform-skill" ~/.claude/plugins/terraform-skill
```

To check it loaded, the README suggests this prompt: "Create a Terraform module with testing for an S3 bucket". If the skill is active, the agent should reach for the module structure and testing guidance rather than improvising. The README's stated expectation is that Claude picks up the skill automatically when working with Terraform or OpenTofu code. If your agent answers that prompt with a flat main.tf and no test plan, the skill is not being loaded, and the problem is the discovery path rather than the content.

## The companion plugin, and why the split is deliberate

The README recommends installing code-intelligence alongside terraform-skill, from the same marketplace:

```bash
/plugin marketplace add antonbabenko/agent-plugins
/plugin install code-intelligence@antonbabenko
```

code-intelligence holds the general, any-language rules for navigating code: when to use a language server versus plain text or fuzzy search, how to anchor a lookup to a position, what to do when a tool fails, and how to signal that one tool has been swapped for another. The README frames terraform-skill as the Terraform-specific version of those rules. Two stated benefits: fewer tokens, because the rules live in one place and load on demand instead of being repeated in every language skill, and more accurate lookups by meaning rather than text.

That split is a real design decision and it has a cost. Installing terraform-skill alone gives you Terraform conventions but not the code-navigation rules, so an agent may still grep for a symbol when a language server would answer faster. The README treats the pair as recommended rather than required, which is honest, but the token argument only pays off if you install more than one language skill.

## Where the skill stops: it advises, it does not execute

This is a guidance package. Nothing in the README describes the skill running terraform plan, terraform apply, or state operations on your behalf. The one execution-adjacent piece is the optional read-only HashiCorp terraform-mcp-server registered through Kiro's mcp.json, and the README states the guidance works without it. If your goal is an agent that opens pull requests against live infrastructure, this is not that tool.

The second boundary is provider coverage as a claim rather than a guarantee. The README says AWS, Azure and GCP are all first-class and that asking for the Azure or GCP equivalent of any pattern maps to that provider. That is a statement about how the skill responds, not a published matrix of verified examples per provider, and the README does not enumerate which patterns have been checked against which cloud. Treat non-AWS output as something to review rather than something to trust by default.

The third is version drift. The repository is at v1.17.1, released on 2026-06-03, with v1.17.0 on 2026-05-30 and v1.16.0 on 2026-05-24. Three releases in ten days is a fast cadence for a set of written rules, and the last push was on 2026-07-03. If you pin a clone, you are pinning guidance that upstream is still revising. If you install through a marketplace, you get the current text, and your agent's advice changes without a commit in your repository.

## Terragrunt, Terratest and native tests: what the decision matrix actually decides

The README lists a decision matrix for native tests versus Terratest, plus testing workflows split into static, integration and E2E. That is the most concrete thing the skill offers, because the choice between Terraform's native test framework and Terratest is a genuine fork with different costs: native tests keep you inside the Terraform binary, while Terratest pulls in a Go toolchain and a test harness you now maintain. A skill that forces the agent to state which side of that line it is choosing is more useful than one that silently picks.

The same logic applies to module development. The README covers structure and naming conventions, versioning strategies, and public versus private module patterns. For teams that already publish modules, the public-versus-private distinction is the one that changes behaviour, since public modules carry compatibility expectations that internal ones do not.

Terragrunt does not appear in the README's feature list. People search for it in connection with this project, but the README describes Terraform and OpenTofu guidance, not a Terragrunt layer. If your stack is Terragrunt-first, assume the skill will not speak to your wrapper conventions and check before adopting.

## Licence, maintenance and what an upgrade costs you

The repository carries an Apache 2.0 licence badge in the README and a LICENSE file at the top level, while the repository metadata reports the licence as NOASSERTION. Those two signals disagree. Read LICENSE directly before you redistribute anything, and note that Apache 2.0 includes a patent grant and requires you to preserve notices, which matters if you fork the skill into an internal plugin. This is not legal advice; it is a reason to open the file.

The maintenance picture is straightforward. The repository is not archived and the last push was on 2026-07-03, so it is current rather than dormant. The upgrade cost is unusually low for a dependency of this kind: there is no compiled artifact and no runtime, so updating means pulling new text. On the manual symlink route that is a git pull in your clone. On the marketplace route it is whatever your host does when it refreshes plugins, and the README documents per-host update commands for some hosts, for example gemini extensions update terraform-skill and, for Codex, cd ~/.agents/skills/terraform-skill && git pull.

The real upgrade risk is behavioural, not technical. Because the skill changes what your agent suggests, a refresh can alter review outcomes across the team with no diff in any repository. If that matters, pin a clone and review upstream changes before pulling.

## Conclusion

Adopt it if your team already uses an Agent Skills-compatible coding agent and keeps hitting the same Terraform mistakes: hand-rolled module layouts, no test strategy, ad hoc state backends. Skip it if you want an agent to run terraform plan or apply for you, or if you do not use Terraform or OpenTofu at all. Before rolling it out, check whether the marketplace clash described in the README applies to your setup, and confirm which version of the skill your agent actually loaded, since the repository is a moving target at v1.17.1.

## FAQ

### What does terraform-skill provide to Claude when writing Terraform?

It supplies best-practice guidance covering testing frameworks, module development, state management, CI/CD integration, security and compliance, and quick-reference decision flowcharts. The README says Claude picks up the skill automatically when working with Terraform or OpenTofu code.

### What is terraform-skill?

It is an Agent Skill for Terraform and OpenTofu aimed at AI coding agents such as Claude Code, Cursor, Copilot, Gemini CLI, OpenCode, Codex and Kiro. It is guidance that the agent loads, not a tool that runs Terraform commands.

### Is terraform-skill still relevant in 2026?

The repository is not archived and the last push was on 2026-07-03, with v1.17.1 released on 2026-06-03. Whether it stays relevant depends on your agent host still supporting Agent Skills discovery paths, which the README lists per host.

### What exactly is Terraform used for?

The skill's guidance covers Terraform and OpenTofu as infrastructure-as-code tools: module structure, state backends and locking, testing, and CI/CD workflows for infrastructure code. The README does not give a general introduction to the tool itself.

## Sources

- [antonbabenko/terraform-skill on GitHub](https://github.com/antonbabenko/terraform-skill)
- [Issues](https://github.com/antonbabenko/terraform-skill/issues)
- [README](https://github.com/antonbabenko/terraform-skill/blob/master/README.md)
- [Releases](https://github.com/antonbabenko/terraform-skill/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/antonbabenko-terraform-skill
