Official agent skill

Avm Tf Conftest

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Conftest

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-conftest -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-conftest --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-conftest .claude/skills/avm-tf-conftest && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-conftest
GitHub stars
135
Token cost
~1.1k tokens
SKILL.md length
453 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

  • Works in 4 steps: Read the current AVM OPA and Conftest… → Read the current… → Locate the reported policy in… → …
  • An AVM Terraform task involves Conftest
  • SKILL.md covers Read current sources first, Run the managed policy check, Exception location and scope and APRL exceptions, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Avm Tf Conftest is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny", and "avm check policy".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Microsoft Azure and Terraform. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • An AVM Terraform task involves Conftest
  • Policy findings
  • Policy exceptions
  • Files under an example exceptions directory

Example prompts

  • “conftest”
  • “AVMSEC”
  • “policy failure”
  • “/avm-tf-conftest”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the current AVM OPA and Conftest policy exception guidance.
  2. Read the current Azure/policy-library-avm documentation.
  3. Locate the reported policy in Azure/policy-library-avm and confirm its package, exact deny_ identifier, provider implementation, and…
  4. Check the planned values that caused the finding before deciding that the rule is inapplicable.

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are powershell and rego).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • azure.github.io
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Conftest loads about 1.1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 453 words, ~1,093 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-conftest/SKILL.md (or your agent's skills folder).
name
avm-tf-conftest
description
Use whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny_", and "avm check policy".

AVM Terraform Conftest

Use Conftest through Avm.Authoring. Fix the planned configuration instead of adding an exception unless the policy genuinely does not apply to the example.

Read current sources first

Before diagnosing a finding or adding an exception:

  1. Read the current AVM OPA and Conftest policy exception guidance.
  2. Read the current Azure/policy-library-avm documentation.
  3. Locate the reported policy in Azure/policy-library-avm and confirm its package, exact deny_ identifier, provider implementation, and expected behavior.
  4. Check the planned values that caused the finding before deciding that the rule is inapplicable.

Do not copy an exception from another module without verifying the current rule source and the example's plan.

Run the managed policy check

pwsh
Import-Module Avm.Authoring
avm version
avm check policy

avm check policy creates plans for examples and evaluates both Azure Proactive Resiliency Library (APRL) and AVM Security (AVMSEC) policies through Conftest. It requires Azure credentials for plan generation. The full clean-worktree gate also runs policy checks:

pwsh
avm pr-check

If the version gate reports a stale installation, run avm update, re-import the module, and retry. Do not replace the managed command with a separately installed Conftest binary or a hand-built policy checkout.

Exception location and scope

Place exception files in the failing example:

text
examples/<example-name>/exceptions/<descriptive-name>.rego

An exception in this directory applies only while evaluating that example. Use a descriptive filename and keep different Rego packages in separate files.

Every exception must:

  • name only the policy identifiers that are genuinely inapplicable;
  • explain why the example cannot or should not comply;
  • link an issue or authoritative source when the exception is temporary or depends on an upstream limitation; and
  • remain narrower than excluding the example from policy or E2E validation.

Never use an empty rule identifier. Conftest treats it as an exception for unqualified deny or violation rules. Do not exclude an entire policy family merely to make the check pass.

Show full SKILL.md (155 more words)Show less

APRL exceptions

APRL policies use the Azure_Proactive_Resiliency_Library_v2 package. The exception identifier is the suffix of the policy's deny_<identifier> rule:

rego
package Azure_Proactive_Resiliency_Library_v2

import rego.v1

# The service does not support zones in the region used by this example.
exception contains rules if {
  rules = ["configure_aks_default_node_pool_zones"]
}

Do not include the deny_ prefix in rules.

AVMSEC exceptions

AVMSEC policies use the avmsec package. Findings and policy source identify rules with names such as deny_AVM_SEC_137; use the suffix without deny_:

rego
package avmsec

import rego.v1

# AVM_SEC_137 does not apply for the documented reason tracked in <issue-url>.
exception contains rules if {
  rules = ["AVM_SEC_137"]
}

The policy library exposes severity collections such as rules_below_high and rules_below_medium. Do not use those broad collections for a normal module example exception; list exact policy identifiers so unrelated security checks remain active.

Validate the result

After adding or changing an exception:

  1. Run avm check policy.
  2. Confirm the intended finding is reported as an exception rather than silently disappearing.
  3. Confirm no unrelated APRL or AVMSEC findings were suppressed.
  4. Review whether the example can be changed to remove the exception.

Conftest reports exceptions separately from passes, warnings, and failures. Treat that exception count as review evidence, not as a clean-policy result.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-conftest of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Conftest next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Conftest compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Conftest this skillAzure/terraform-azurerm-avm-ptn-alz135—~1.1kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark716—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql412—~3.7kAutomated safety check: PassCustom licence
Tirith MigrateStackGuardian/tirith170—~1.7kAutomated safety check: PassApache-2.0
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    716 GitHub stars~843 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    412 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Tirith Standards

    StackGuardian/tirith

    Generate a Tirith policy set for an existing Terraform or OpenTofu repository, covering organization standards such as required tags, naming conventions, allowed regions, permitted resource types…

    170 GitHub stars~2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Interfaces

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

    135 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Avm Tf Conftest

What does Avm Tf Conftest do?

A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Avm Tf Conftest is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

When should I use Avm Tf Conftest?

Avm Tf Conftest fits situations like: an AVM Terraform task involves Conftest; policy findings; policy exceptions; files under an example exceptions directory.

How do I install Avm Tf Conftest in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-conftest -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-conftest in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-conftest in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Conftest in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-conftest -a codex`. Or copy the skill folder (.github/skills/avm-tf-conftest in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-conftest in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Conftest in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-conftest -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-conftest, .gemini/skills/avm-tf-conftest, .github/skills/avm-tf-conftest and .opencode/skills/avm-tf-conftest in your project.

What does Avm Tf Conftest need to run?

SKILL.md names no scripts, command-line tools or credentials: Avm Tf Conftest is instructions for the agent only.

Does Avm Tf Conftest access the network?

SKILL.md names 2 domains. As links in the text: azure.github.io and github.com. This is read from the text; nothing was executed.

Is Avm Tf Conftest safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Conftest use?

Avm Tf Conftest is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Conftest use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Conftest?

Skills that share tags, products or a category with Avm Tf Conftest: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 716 stars), Provider Verification (mondoohq/mql, 412 stars) and Tirith Migrate (StackGuardian/tirith, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Conftest?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.