Agent skill

Terraform and OpenTofu Guide

by agentscope-ai in agentscope-ai/QwenPaw

Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

Apache-2.0Auto-check passedDevOps & Cloud

Install Terraform and OpenTofu Guide

skills CLI
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .claude/skills/terraform-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
terraform-skill
GitHub stars
36k
Used in
6 other repos
Token cost
~4.2k tokens
SKILL.md length
1,200 words
Files
7 (incl. references)
Skills in repo
20
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

  • Works in 2 steps: Code Structure Philosophy → Naming Conventions
  • Creating a new Terraform or OpenTofu module
  • SKILL.md covers When to Use This Skill, Core Principles, Testing Strategy Framework and Code Structure Standards, plus 7 more sections
  • Calls terraform, trivy and tofu

What it does

The skill covers creating modules, choosing between testing approaches, setting up CI/CD for infrastructure as code, reviewing or refactoring existing projects, and structuring multi-environment deployments. It is based on terraform-best-practices.com and enterprise experience. It leaves out basic syntax questions, provider-specific API reference and cloud questions unrelated to Terraform or OpenTofu.

Core guidance lays out a module hierarchy that runs from resource modules through infrastructure modules to compositions, and a directory layout that separates environments such as prod and staging from reusable modules, with examples folders doubling as documentation and integration-test fixtures. Modules stay small with a single responsibility. Naming favors descriptive, contextual resource names and reserves the name this for the only resource of a type in a module.

Six reference files go deeper on code patterns, module patterns, testing frameworks, CI/CD workflows, security and compliance, and a quick reference. The description names the native test framework and Terratest for testing and trivy and checkov for security scanning.

When your agent uses it

  • Creating a new Terraform or OpenTofu module
  • Deciding between validate, plan, native tests and Terratest
  • Setting up CI/CD pipelines for infrastructure code
  • Reviewing or refactoring an existing Terraform project
  • Adding security scanning with trivy or checkov

Example prompts

  • “Create a VPC module with subnets and security groups, and set up native Terraform tests for it.”
  • “Review our infrastructure repo layout and propose how to separate prod from staging.”
  • “Add a CI pipeline that runs validate, plan and a trivy scan on every pull request.”

Requirements

  • Terraform or OpenTofu

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Code Structure Philosophy
  2. Naming Conventions

What it can do on your machine

Read from SKILL.md and the folder at commit 3b961b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform
    • trivy
    • tofu

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Terraform and OpenTofu Guide loads about 4.2k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~28k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentscope-ai/QwenPaw at commit 3b961b7, republished under its Apache-2.0 licence (© agentscope-ai). 1,200 words, ~4,185 tokens.

Download SKILL.mdSave it as .claude/skills/terraform-skill/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
terraform-skill
description
Use when working with Terraform or OpenTofu - creating modules, writing tests (native test framework, Terratest), setting up CI/CD pipelines, reviewing configurations, choosing between testing approaches, debugging state issues, implementing security scanning (trivy, checkov), or making infrastructure-as-code architecture decisions
license
Apache-2.0
metadata.author
Anton Babenko
metadata.version
1.6.0

Terraform Skill for Claude

Comprehensive Terraform and OpenTofu guidance covering testing, modules, CI/CD, and production patterns. Based on terraform-best-practices.com and enterprise experience.

When to Use This Skill

Activate this skill when:

  • Creating new Terraform or OpenTofu configurations or modules
  • Setting up testing infrastructure for IaC code
  • Deciding between testing approaches (validate, plan, frameworks)
  • Structuring multi-environment deployments
  • Implementing CI/CD for infrastructure-as-code
  • Reviewing or refactoring existing Terraform/OpenTofu projects
  • Choosing between module patterns or state management approaches

Don't use this skill for:

  • Basic Terraform/OpenTofu syntax questions (Claude knows this)
  • Provider-specific API reference (link to docs instead)
  • Cloud platform questions unrelated to Terraform/OpenTofu

Core Principles

1. Code Structure Philosophy

Module Hierarchy:

TypeWhen to UseScope
Resource ModuleSingle logical group of connected resourcesVPC + subnets, Security group + rules
Infrastructure ModuleCollection of resource modules for a purposeMultiple resource modules in one region/account
CompositionComplete infrastructureSpans multiple regions/accounts

Hierarchy: Resource → Resource Module → Infrastructure Module → Composition

Directory Structure:

environments/        # Environment-specific configurations
├── prod/
├── staging/
└── dev/

modules/            # Reusable modules
├── networking/
├── compute/
└── data/

examples/           # Module usage examples (also serve as tests)
├── complete/
└── minimal/

Key principle from terraform-best-practices.com:

  • Separate environments (prod, staging) from modules (reusable components)
  • Use examples/ as both documentation and integration test fixtures
  • Keep modules small and focused (single responsibility)

For detailed module architecture, see: Code Patterns: Module Types & Hierarchy

2. Naming Conventions

Resources:

hcl
# Good: Descriptive, contextual
resource "aws_instance" "web_server" { }
resource "aws_s3_bucket" "application_logs" { }

# Good: "this" for singleton resources (only one of that type)
resource "aws_vpc" "this" { }
resource "aws_security_group" "this" { }

# Avoid: Generic names for non-singletons
resource "aws_instance" "main" { }
resource "aws_s3_bucket" "bucket" { }

Singleton Resources:

Use "this" when your module creates only one resource of that type:

✅ DO:

hcl
resource "aws_vpc" "this" {}           # Module creates one VPC
resource "aws_security_group" "this" {}  # Module creates one SG

❌ DON'T use "this" for multiple resources:

hcl
resource "aws_subnet" "this" {}  # If creating multiple subnets

Use descriptive names when creating multiple resources of the same type.

Variables:

hcl
# Prefix with context when needed
var.vpc_cidr_block          # Not just "cidr"
var.database_instance_class # Not just "instance_class"

Files:

  • main.tf - Primary resources
  • variables.tf - Input variables
  • outputs.tf - Output values
  • versions.tf - Provider versions
  • data.tf - Data sources (optional)

Testing Strategy Framework

Decision Matrix: Which Testing Approach?
Your SituationRecommended ApproachToolsCost
Quick syntax checkStatic analysisterraform validate, fmtFree
Pre-commit validationStatic + lintvalidate, tflint, trivy, checkovFree
Terraform 1.6+, simple logicNative test frameworkBuilt-in terraform testFree-Low
Pre-1.6, or Go expertiseIntegration testingTerratestLow-Med
Security/compliance focusPolicy as codeOPA, SentinelFree
Cost-sensitive workflowMock providers (1.7+)Native tests + mockingFree
Multi-cloud, complexFull integrationTerratest + real infraMed-High
Testing Pyramid for Infrastructure
        /\
       /  \          End-to-End Tests (Expensive)
      /____\         - Full environment deployment
     /      \        - Production-like setup
    /________\
   /          \      Integration Tests (Moderate)
  /____________\     - Module testing in isolation
 /              \    - Real resources in test account
/________________\   Static Analysis (Cheap)
                     - validate, fmt, lint
                     - Security scanning
Native Test Best Practices (1.6+)

Before generating test code:

  1. Validate schemas with Terraform MCP:

    Search provider docs → Get resource schema → Identify block types
  2. Choose correct command mode:

    • command = plan - Fast, for input validation
    • command = apply - Required for computed values and set-type blocks
  3. Handle set-type blocks correctly:

    • Cannot index with [0]
    • Use for expressions to iterate
    • Or use command = apply to materialize

Common patterns:

  • S3 encryption rules: set (use for expressions)
  • Lifecycle transitions: set (use for expressions)
  • IAM policy statements: set (use for expressions)

For detailed testing guides, see:

Code Structure Standards

Resource Block Ordering

Strict ordering for consistency:

  1. count or for_each FIRST (blank line after)
  2. Other arguments
  3. tags as last real argument
  4. depends_on after tags (if needed)
  5. lifecycle at the very end (if needed)
hcl
# ✅ GOOD - Correct ordering
resource "aws_nat_gateway" "this" {
  count = var.create_nat_gateway ? 1 : 0

  allocation_id = aws_eip.this[0].id
  subnet_id     = aws_subnet.public[0].id

  tags = {
    Name = "${var.name}-nat"
  }

  depends_on = [aws_internet_gateway.this]

  lifecycle {
    create_before_destroy = true
  }
}
Variable Block Ordering
  1. description (ALWAYS required)
  2. type
  3. default
  4. validation
  5. nullable (when setting to false)
hcl
variable "environment" {
  description = "Environment name for resource tagging"
  type        = string
  default     = "dev"

  validation {
    condition     = contains(["dev", "staging", "prod"], var.environment)
    error_message = "Environment must be one of: dev, staging, prod."
  }

  nullable = false
}

For complete structure guidelines, see: Code Patterns: Block Ordering & Structure

Count vs For_Each: When to Use Each

Quick Decision Guide
ScenarioUseWhy
Boolean condition (create or don't)count = condition ? 1 : 0Simple on/off toggle
Simple numeric replicationcount = 3Fixed number of identical resources
Items may be reordered/removedfor_each = toset(list)Stable resource addresses
Reference by keyfor_each = mapNamed access to resources
Multiple named resourcesfor_eachBetter maintainability
Common Patterns

Boolean conditions:

hcl
# ✅ GOOD - Boolean condition
resource "aws_nat_gateway" "this" {
  count = var.create_nat_gateway ? 1 : 0
  # ...
}

Stable addressing with for_each:

hcl
# ✅ GOOD - Removing "us-east-1b" only affects that subnet
resource "aws_subnet" "private" {
  for_each = toset(var.availability_zones)

  availability_zone = each.key
  # ...
}

# ❌ BAD - Removing middle AZ recreates all subsequent subnets
resource "aws_subnet" "private" {
  count = length(var.availability_zones)

  availability_zone = var.availability_zones[count.index]
  # ...
}

For migration guides and detailed examples, see: Code Patterns: Count vs For_Each

Locals for Dependency Management

Use locals to ensure correct resource deletion order:

hcl
# Problem: Subnets might be deleted after CIDR blocks, causing errors
# Solution: Use try() in locals to hint deletion order

locals {
  # References secondary CIDR first, falling back to VPC
  # Forces Terraform to delete subnets before CIDR association
  vpc_id = try(
    aws_vpc_ipv4_cidr_block_association.this[0].vpc_id,
    aws_vpc.this.id,
    ""
  )
}

resource "aws_vpc" "this" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_vpc_ipv4_cidr_block_association" "this" {
  count = var.add_secondary_cidr ? 1 : 0

  vpc_id     = aws_vpc.this.id
  cidr_block = "10.1.0.0/16"
}

resource "aws_subnet" "public" {
  vpc_id     = local.vpc_id  # Uses local, not direct reference
  cidr_block = "10.1.0.0/24"
}

Why this matters:

  • Prevents deletion errors when destroying infrastructure
  • Ensures correct dependency order without explicit depends_on
  • Particularly useful for VPC configurations with secondary CIDR blocks

For detailed examples, see: Code Patterns: Locals for Dependency Management

Module Development

Standard Module Structure
my-module/
├── README.md           # Usage documentation
├── main.tf             # Primary resources
├── variables.tf        # Input variables with descriptions
├── outputs.tf          # Output values
├── versions.tf         # Provider version constraints
├── examples/
│   ├── minimal/        # Minimal working example
│   └── complete/       # Full-featured example
└── tests/              # Test files
    └── module_test.tftest.hcl  # Or .go
Best Practices Summary

Variables:

  • ✅ Always include description
  • ✅ Use explicit type constraints
  • ✅ Provide sensible default values where appropriate
  • ✅ Add validation blocks for complex constraints
  • ✅ Use sensitive = true for secrets

Outputs:

  • ✅ Always include description
  • ✅ Mark sensitive outputs with sensitive = true
  • ✅ Consider returning objects for related values
  • ✅ Document what consumers should do with each output

For detailed module patterns, see:

CI/CD Integration

Show full SKILL.md (491 more words)Show less
  1. Validate - Format check + syntax validation + linting
  2. Test - Run automated tests (native or Terratest)
  3. Plan - Generate and review execution plan
  4. Apply - Execute changes (with approvals for production)
Cost Optimization Strategy
  1. Use mocking for PR validation (free)
  2. Run integration tests only on main branch (controlled cost)
  3. Implement auto-cleanup (prevent orphaned resources)
  4. Tag all test resources (track spending)

For complete CI/CD templates, see:

Security & Compliance

Essential Security Checks
bash
# Static security scanning
trivy config .
checkov -d .
Common Issues to Avoid

❌ Don't:

  • Store secrets in variables
  • Use default VPC
  • Skip encryption
  • Open security groups to 0.0.0.0/0

✅ Do:

  • Use AWS Secrets Manager / Parameter Store
  • Create dedicated VPCs
  • Enable encryption at rest
  • Use least-privilege security groups

For detailed security guidance, see:

Version Management

Version Constraint Syntax
hcl
version = "5.0.0"      # Exact (avoid - inflexible)
version = "~> 5.0"     # Recommended: 5.0.x only
version = ">= 5.0"     # Minimum (risky - breaking changes)
Strategy by Component
ComponentStrategyExample
TerraformPin minor versionrequired_version = "~> 1.9"
ProvidersPin major versionversion = "~> 5.0"
Modules (prod)Pin exact versionversion = "5.1.2"
Modules (dev)Allow patch updatesversion = "~> 5.1"
Update Workflow
bash
# Lock versions initially
terraform init              # Creates .terraform.lock.hcl

# Update to latest within constraints
terraform init -upgrade     # Updates providers

# Review and test
terraform plan

For detailed version management, see: Code Patterns: Version Management

Modern Terraform Features (1.0+)

Feature Availability by Version
FeatureVersionUse Case
try() function0.13+Safe fallbacks, replaces element(concat())
nullable = false1.1+Prevent null values in variables
moved blocks1.1+Refactor without destroy/recreate
optional() with defaults1.3+Optional object attributes
Native testing1.6+Built-in test framework
Mock providers1.7+Cost-free unit testing
Provider functions1.8+Provider-specific data transformation
Cross-variable validation1.9+Validate relationships between variables
Write-only arguments1.11+Secrets never stored in state
Quick Examples
hcl
# try() - Safe fallbacks (0.13+)
output "sg_id" {
  value = try(aws_security_group.this[0].id, "")
}

# optional() - Optional attributes with defaults (1.3+)
variable "config" {
  type = object({
    name    = string
    timeout = optional(number, 300)  # Default: 300
  })
}

# Cross-variable validation (1.9+)
variable "environment" { type = string }
variable "backup_days" {
  type = number
  validation {
    condition     = var.environment == "prod" ? var.backup_days >= 7 : true
    error_message = "Production requires backup_days >= 7"
  }
}

For complete patterns and examples, see: Code Patterns: Modern Terraform Features

Version-Specific Guidance

Terraform 1.0-1.5
  • Use Terratest for testing
  • No native testing framework available
  • Focus on static analysis and plan validation
Terraform 1.6+ / OpenTofu 1.6+
  • New: Native terraform test / tofu test command
  • Consider migrating from external frameworks for simple tests
  • Keep Terratest only for complex integration tests
Terraform 1.7+ / OpenTofu 1.7+
  • New: Mock providers for unit testing
  • Reduce cost by mocking external dependencies
  • Use real integration tests for final validation
Terraform vs OpenTofu

Both are fully supported by this skill. For licensing, governance, and feature comparison, see Quick Reference: Terraform vs OpenTofu.

Detailed Guides

This skill uses progressive disclosure - essential information is in this main file, detailed guides are available when needed:

📚 Reference Files:

  • Testing Frameworks - In-depth guide to static analysis, native tests, and Terratest
  • Module Patterns - Module structure, variable/output best practices, ✅ DO vs ❌ DON'T patterns
  • CI/CD Workflows - GitHub Actions, GitLab CI templates, cost optimization, automated cleanup
  • Security & Compliance - Trivy/Checkov integration, secrets management, compliance testing
  • Quick Reference - Command cheat sheets, decision flowcharts, troubleshooting guide

How to use: When you need detailed information on a topic, reference the appropriate guide. Claude will load it on demand to provide comprehensive guidance.

License

This skill is licensed under the Apache License 2.0. See the LICENSE file for full terms.

Copyright © 2026 Anton Babenko

© agentscope-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/bundle/cloudpaw/skills/terraform-skill of agentscope-ai/QwenPaw.

  • SKILL.md
  • references/ci-cd-workflows.md
  • references/code-patterns.md
  • references/module-patterns.md
  • references/quick-reference.md
  • references/security-compliance.md
  • references/testing-frameworks.md

Open the folder on GitHubat commit 3b961b7

Used in 6 other repositories

We found 15 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 6 other GitHub owners. This page covers the copy in agentscope-ai/QwenPaw, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Terraform and OpenTofu Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Terraform and OpenTofu Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Terraform and OpenTofu Guide this skillagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Tirith PoliciesStackGuardian/tirith170—~1.8kAutomated safety check: PassApache-2.0
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Tirith Policies

    StackGuardian/tirith

    Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…

    170 GitHub stars~1.8k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check: warnings

More from agentscope-ai/QwenPaw

All 20 skills in this repo
  • Make Skill

    agentscope-ai/QwenPaw

    Turns reusable decisions, templates or workflows from the current conversation into a new workspace skill through plan, approval, draft, validation and publication.

    36k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • QwenPaw Make Skill

    agentscope-ai/QwenPaw

    Creates a focused workspace skill from the current conversation in QwenPaw, moving through a planning, approval, drafting, validation and publishing script pipeline.

    36k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • QwenPaw Scheduled Tasks

    agentscope-ai/QwenPaw

    Creates and manages scheduled or recurring jobs with the qwenpaw cron commands, always tied to an explicit agent ID and a confirmed target channel.

    36k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • DOCX Creation and Editing

    agentscope-ai/QwenPaw

    Creates, reads and edits Word .docx files, including tracked changes and comments, using docx-js for new files and XML editing for existing ones.

    36k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Mailbox Operations Hub

    agentscope-ai/QwenPaw

    Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.

    36k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • OMP Sub-Agent Role Presets

    agentscope-ai/QwenPaw

    Gives the allowed_tools and skills preset for each OMP sub-agent role, to apply when calling spawn_subagent.

    36k GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Terraform and OpenTofu Guide

What does Terraform and OpenTofu Guide do?

Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning. The skill covers creating modules, choosing between testing approaches, setting up CI/CD for infrastructure as code, reviewing or refactoring existing projects, and structuring multi-environment deployments.com and enterprise experience.

When should I use Terraform and OpenTofu Guide?

Terraform and OpenTofu Guide fits situations like: creating a new Terraform or OpenTofu module; deciding between validate, plan, native tests and Terratest; setting up CI/CD pipelines for infrastructure code; reviewing or refactoring an existing Terraform project.

How do I install Terraform and OpenTofu Guide in Claude Code?

Run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a claude-code`. Or copy the skill folder (plugins/bundle/cloudpaw/skills/terraform-skill in agentscope-ai/QwenPaw) into .claude/skills/terraform-skill in your project. Claude Code loads it when a task matches its description.

How do I install Terraform and OpenTofu Guide in Codex?

Run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a codex`. Or copy the skill folder (plugins/bundle/cloudpaw/skills/terraform-skill in agentscope-ai/QwenPaw) into .agents/skills/terraform-skill in your project. Codex loads it when a task matches its description.

Can I use Terraform and OpenTofu Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform-skill, .gemini/skills/terraform-skill, .github/skills/terraform-skill and .opencode/skills/terraform-skill in your project.

What does Terraform and OpenTofu Guide need to run?

Going by SKILL.md and its folder, Terraform and OpenTofu Guide needs the command-line tools its instructions call (terraform, trivy and tofu). Our summary lists: Terraform or OpenTofu.

Does Terraform and OpenTofu Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Terraform and OpenTofu Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Terraform and OpenTofu Guide use?

Terraform and OpenTofu Guide is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Terraform and OpenTofu Guide use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to Terraform and OpenTofu Guide?

Skills that share tags, products or a category with Terraform and OpenTofu Guide: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Tirith Policies (StackGuardian/tirith, 170 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Terraform and OpenTofu Guide?

agentscope-ai (a GitHub organization) maintains it in agentscope-ai/QwenPaw, which has 35,548 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 10, 2026.

Source: agentscope-ai/QwenPaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.