Sca Trivy
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .claude/skills/terraform-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .claude/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .agents/skills/terraform-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .agents/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .cursor/skills/terraform-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .cursor/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/agentscope-ai/QwenPaw.git --path plugins/bundle/cloudpaw/skills/terraform-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .gemini/skills/terraform-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .gemini/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install agentscope-ai/QwenPaw terraform-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .github/skills/terraform-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .github/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install agentscope-ai/QwenPaw terraform-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentscope-ai/QwenPaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/bundle/cloudpaw/skills/terraform-skill .opencode/skills/terraform-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "terraform-skill" agent skill from https://github.com/agentscope-ai/QwenPaw/tree/main/plugins/bundle/cloudpaw/skills/terraform-skill into .opencode/skills/terraform-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
terraform-skillGuidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
The skill covers creating modules, choosing between testing approaches, setting up CI/CD for infrastructure as code, reviewing or refactoring existing projects, and structuring multi-environment deployments. It is based on terraform-best-practices.com and enterprise experience. It leaves out basic syntax questions, provider-specific API reference and cloud questions unrelated to Terraform or OpenTofu.
Core guidance lays out a module hierarchy that runs from resource modules through infrastructure modules to compositions, and a directory layout that separates environments such as prod and staging from reusable modules, with examples folders doubling as documentation and integration-test fixtures. Modules stay small with a single responsibility. Naming favors descriptive, contextual resource names and reserves the name this for the only resource of a type in a module.
Six reference files go deeper on code patterns, module patterns, testing frameworks, CI/CD workflows, security and compliance, and a quick reference. The description names the native test framework and Terratest for testing and trivy and checkov for security scanning.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3b961b7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
terraformtrivytofuFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Terraform and OpenTofu Guide loads about 4.2k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,200 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from agentscope-ai/QwenPaw at commit 3b961b7, republished under its Apache-2.0 licence (© agentscope-ai). 1,200 words, ~4,185 tokens.
.claude/skills/terraform-skill/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Comprehensive Terraform and OpenTofu guidance covering testing, modules, CI/CD, and production patterns. Based on terraform-best-practices.com and enterprise experience.
Activate this skill when:
Don't use this skill for:
Module Hierarchy:
| Type | When to Use | Scope |
|---|---|---|
| Resource Module | Single logical group of connected resources | VPC + subnets, Security group + rules |
| Infrastructure Module | Collection of resource modules for a purpose | Multiple resource modules in one region/account |
| Composition | Complete infrastructure | Spans multiple regions/accounts |
Hierarchy: Resource → Resource Module → Infrastructure Module → Composition
Directory Structure:
environments/ # Environment-specific configurations
├── prod/
├── staging/
└── dev/
modules/ # Reusable modules
├── networking/
├── compute/
└── data/
examples/ # Module usage examples (also serve as tests)
├── complete/
└── minimal/Key principle from terraform-best-practices.com:
For detailed module architecture, see: Code Patterns: Module Types & Hierarchy
Resources:
# Good: Descriptive, contextual
resource "aws_instance" "web_server" { }
resource "aws_s3_bucket" "application_logs" { }
# Good: "this" for singleton resources (only one of that type)
resource "aws_vpc" "this" { }
resource "aws_security_group" "this" { }
# Avoid: Generic names for non-singletons
resource "aws_instance" "main" { }
resource "aws_s3_bucket" "bucket" { }Singleton Resources:
Use "this" when your module creates only one resource of that type:
✅ DO:
resource "aws_vpc" "this" {} # Module creates one VPC
resource "aws_security_group" "this" {} # Module creates one SG❌ DON'T use "this" for multiple resources:
resource "aws_subnet" "this" {} # If creating multiple subnetsUse descriptive names when creating multiple resources of the same type.
Variables:
# Prefix with context when needed
var.vpc_cidr_block # Not just "cidr"
var.database_instance_class # Not just "instance_class"Files:
main.tf - Primary resourcesvariables.tf - Input variablesoutputs.tf - Output valuesversions.tf - Provider versionsdata.tf - Data sources (optional)| Your Situation | Recommended Approach | Tools | Cost |
|---|---|---|---|
| Quick syntax check | Static analysis | terraform validate, fmt | Free |
| Pre-commit validation | Static + lint | validate, tflint, trivy, checkov | Free |
| Terraform 1.6+, simple logic | Native test framework | Built-in terraform test | Free-Low |
| Pre-1.6, or Go expertise | Integration testing | Terratest | Low-Med |
| Security/compliance focus | Policy as code | OPA, Sentinel | Free |
| Cost-sensitive workflow | Mock providers (1.7+) | Native tests + mocking | Free |
| Multi-cloud, complex | Full integration | Terratest + real infra | Med-High |
/\
/ \ End-to-End Tests (Expensive)
/____\ - Full environment deployment
/ \ - Production-like setup
/________\
/ \ Integration Tests (Moderate)
/____________\ - Module testing in isolation
/ \ - Real resources in test account
/________________\ Static Analysis (Cheap)
- validate, fmt, lint
- Security scanningBefore generating test code:
Validate schemas with Terraform MCP:
Search provider docs → Get resource schema → Identify block typesChoose correct command mode:
command = plan - Fast, for input validationcommand = apply - Required for computed values and set-type blocksHandle set-type blocks correctly:
[0]for expressions to iteratecommand = apply to materializeCommon patterns:
For detailed testing guides, see:
Strict ordering for consistency:
count or for_each FIRST (blank line after)tags as last real argumentdepends_on after tags (if needed)lifecycle at the very end (if needed)# ✅ GOOD - Correct ordering
resource "aws_nat_gateway" "this" {
count = var.create_nat_gateway ? 1 : 0
allocation_id = aws_eip.this[0].id
subnet_id = aws_subnet.public[0].id
tags = {
Name = "${var.name}-nat"
}
depends_on = [aws_internet_gateway.this]
lifecycle {
create_before_destroy = true
}
}description (ALWAYS required)typedefaultvalidationnullable (when setting to false)variable "environment" {
description = "Environment name for resource tagging"
type = string
default = "dev"
validation {
condition = contains(["dev", "staging", "prod"], var.environment)
error_message = "Environment must be one of: dev, staging, prod."
}
nullable = false
}For complete structure guidelines, see: Code Patterns: Block Ordering & Structure
| Scenario | Use | Why |
|---|---|---|
| Boolean condition (create or don't) | count = condition ? 1 : 0 | Simple on/off toggle |
| Simple numeric replication | count = 3 | Fixed number of identical resources |
| Items may be reordered/removed | for_each = toset(list) | Stable resource addresses |
| Reference by key | for_each = map | Named access to resources |
| Multiple named resources | for_each | Better maintainability |
Boolean conditions:
# ✅ GOOD - Boolean condition
resource "aws_nat_gateway" "this" {
count = var.create_nat_gateway ? 1 : 0
# ...
}Stable addressing with for_each:
# ✅ GOOD - Removing "us-east-1b" only affects that subnet
resource "aws_subnet" "private" {
for_each = toset(var.availability_zones)
availability_zone = each.key
# ...
}
# ❌ BAD - Removing middle AZ recreates all subsequent subnets
resource "aws_subnet" "private" {
count = length(var.availability_zones)
availability_zone = var.availability_zones[count.index]
# ...
}For migration guides and detailed examples, see: Code Patterns: Count vs For_Each
Use locals to ensure correct resource deletion order:
# Problem: Subnets might be deleted after CIDR blocks, causing errors
# Solution: Use try() in locals to hint deletion order
locals {
# References secondary CIDR first, falling back to VPC
# Forces Terraform to delete subnets before CIDR association
vpc_id = try(
aws_vpc_ipv4_cidr_block_association.this[0].vpc_id,
aws_vpc.this.id,
""
)
}
resource "aws_vpc" "this" {
cidr_block = "10.0.0.0/16"
}
resource "aws_vpc_ipv4_cidr_block_association" "this" {
count = var.add_secondary_cidr ? 1 : 0
vpc_id = aws_vpc.this.id
cidr_block = "10.1.0.0/16"
}
resource "aws_subnet" "public" {
vpc_id = local.vpc_id # Uses local, not direct reference
cidr_block = "10.1.0.0/24"
}Why this matters:
depends_onFor detailed examples, see: Code Patterns: Locals for Dependency Management
my-module/
├── README.md # Usage documentation
├── main.tf # Primary resources
├── variables.tf # Input variables with descriptions
├── outputs.tf # Output values
├── versions.tf # Provider version constraints
├── examples/
│ ├── minimal/ # Minimal working example
│ └── complete/ # Full-featured example
└── tests/ # Test files
└── module_test.tftest.hcl # Or .goVariables:
descriptiontype constraintsdefault values where appropriatevalidation blocks for complex constraintssensitive = true for secretsOutputs:
descriptionsensitive = trueFor detailed module patterns, see:
For complete CI/CD templates, see:
# Static security scanning
trivy config .
checkov -d .❌ Don't:
✅ Do:
For detailed security guidance, see:
version = "5.0.0" # Exact (avoid - inflexible)
version = "~> 5.0" # Recommended: 5.0.x only
version = ">= 5.0" # Minimum (risky - breaking changes)| Component | Strategy | Example |
|---|---|---|
| Terraform | Pin minor version | required_version = "~> 1.9" |
| Providers | Pin major version | version = "~> 5.0" |
| Modules (prod) | Pin exact version | version = "5.1.2" |
| Modules (dev) | Allow patch updates | version = "~> 5.1" |
# Lock versions initially
terraform init # Creates .terraform.lock.hcl
# Update to latest within constraints
terraform init -upgrade # Updates providers
# Review and test
terraform planFor detailed version management, see: Code Patterns: Version Management
| Feature | Version | Use Case |
|---|---|---|
try() function | 0.13+ | Safe fallbacks, replaces element(concat()) |
nullable = false | 1.1+ | Prevent null values in variables |
moved blocks | 1.1+ | Refactor without destroy/recreate |
optional() with defaults | 1.3+ | Optional object attributes |
| Native testing | 1.6+ | Built-in test framework |
| Mock providers | 1.7+ | Cost-free unit testing |
| Provider functions | 1.8+ | Provider-specific data transformation |
| Cross-variable validation | 1.9+ | Validate relationships between variables |
| Write-only arguments | 1.11+ | Secrets never stored in state |
# try() - Safe fallbacks (0.13+)
output "sg_id" {
value = try(aws_security_group.this[0].id, "")
}
# optional() - Optional attributes with defaults (1.3+)
variable "config" {
type = object({
name = string
timeout = optional(number, 300) # Default: 300
})
}
# Cross-variable validation (1.9+)
variable "environment" { type = string }
variable "backup_days" {
type = number
validation {
condition = var.environment == "prod" ? var.backup_days >= 7 : true
error_message = "Production requires backup_days >= 7"
}
}For complete patterns and examples, see: Code Patterns: Modern Terraform Features
terraform test / tofu test commandBoth are fully supported by this skill. For licensing, governance, and feature comparison, see Quick Reference: Terraform vs OpenTofu.
This skill uses progressive disclosure - essential information is in this main file, detailed guides are available when needed:
📚 Reference Files:
How to use: When you need detailed information on a topic, reference the appropriate guide. Claude will load it on demand to provide comprehensive guidance.
This skill is licensed under the Apache License 2.0. See the LICENSE file for full terms.
Copyright © 2026 Anton Babenko
© agentscope-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in plugins/bundle/cloudpaw/skills/terraform-skill of agentscope-ai/QwenPaw.
Open the folder on GitHubat commit 3b961b7
We found 15 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 6 other GitHub owners. This page covers the copy in agentscope-ai/QwenPaw, which our catalogue first saw on October 7, 2026.
Terraform and OpenTofu Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Terraform and OpenTofu Guide this skillagentscope-ai/QwenPaw | 36k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Tirith PoliciesStackGuardian/tirith | 170 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Devops EngineerYikai-Liao/symusic | 189 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills | 202 | — | ~3.6k | Automated safety check: Pass | MIT |
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
StackGuardian/tirith
Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…
Yikai-Liao/symusic
Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.
thomast1906/github-copilot-agent-skills
Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.
cloudposse/atmos
Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…
agentscope-ai/QwenPaw
Turns reusable decisions, templates or workflows from the current conversation into a new workspace skill through plan, approval, draft, validation and publication.
agentscope-ai/QwenPaw
Creates a focused workspace skill from the current conversation in QwenPaw, moving through a planning, approval, drafting, validation and publishing script pipeline.
agentscope-ai/QwenPaw
Creates and manages scheduled or recurring jobs with the qwenpaw cron commands, always tied to an explicit agent ID and a confirmed target channel.
agentscope-ai/QwenPaw
Creates, reads and edits Word .docx files, including tracked changes and comments, using docx-js for new files and XML editing for existing ones.
agentscope-ai/QwenPaw
Connects, registers, and operates a personal mailbox, reading, searching, sending, and organizing, through a managed mail server for nine domains.
agentscope-ai/QwenPaw
Gives the allowed_tools and skills preset for each OMP sub-agent role, to apply when calling spawn_subagent.
Categories
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning. The skill covers creating modules, choosing between testing approaches, setting up CI/CD for infrastructure as code, reviewing or refactoring existing projects, and structuring multi-environment deployments.com and enterprise experience.
Terraform and OpenTofu Guide fits situations like: creating a new Terraform or OpenTofu module; deciding between validate, plan, native tests and Terratest; setting up CI/CD pipelines for infrastructure code; reviewing or refactoring an existing Terraform project.
Run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a claude-code`. Or copy the skill folder (plugins/bundle/cloudpaw/skills/terraform-skill in agentscope-ai/QwenPaw) into .claude/skills/terraform-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a codex`. Or copy the skill folder (plugins/bundle/cloudpaw/skills/terraform-skill in agentscope-ai/QwenPaw) into .agents/skills/terraform-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentscope-ai/QwenPaw --skill terraform-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform-skill, .gemini/skills/terraform-skill, .github/skills/terraform-skill and .opencode/skills/terraform-skill in your project.
Going by SKILL.md and its folder, Terraform and OpenTofu Guide needs the command-line tools its instructions call (terraform, trivy and tofu). Our summary lists: Terraform or OpenTofu.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Terraform and OpenTofu Guide is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Terraform and OpenTofu Guide: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Tirith Policies (StackGuardian/tirith, 170 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
agentscope-ai (a GitHub organization) maintains it in agentscope-ai/QwenPaw, which has 35,548 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 10, 2026.
Source: agentscope-ai/QwenPaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.