Iac Security
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-tflint .claude/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .claude/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflintType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/avm-tf-tflint .agents/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .agents/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/avm-tf-tflint .cursor/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .cursor/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git --path .github/skills/avm-tf-tflint--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/avm-tf-tflint .gemini/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .gemini/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflintInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/avm-tf-tflint .github/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .github/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/avm-tf-tflint .opencode/skills/avm-tf-tflint && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "avm-tf-tflint" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-tflint into .opencode/skills/avm-tf-tflint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-tflint", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
avm-tf-tflintA skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.
Avm Tf Tflint is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code and Linting and formatting. It works with Terraform and Microsoft Azure. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl and powershell).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comazure.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Avm Tf Tflint loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 847 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 847 words, ~2,187 tokens.
.claude/skills/avm-tf-tflint/SKILL.md (or your agent's skills folder).Use TFLint through Avm.Authoring. Fix violations instead of suppressing them unless the published AVM requirement genuinely does not apply.
Before diagnosing a finding or changing rule configuration:
Azure/tflint-ruleset-avm rule inventory.The published rules guide controls applicability and the supported override process. The released plugin controls valid rule identifiers and configuration. Do not rely on an older module, cached rule name, or this inventory when a live source differs.
Import-Module Avm.Authoring
avm version
avm lintIf the version gate reports a stale installation, run avm update, re-import the module, and retry. Run avm pre-commit before linting when managed sync or transforms can affect the configuration. Use avm pr-check only after committing the complete worktree because it requires a clean worktree.
Do not approximate the managed configuration with a separately installed TFLint binary, custom plugin setup, Make, Porch, or a container.
Use the supported AVM override files by default. They make exceptions visible, reviewable, and consistent across the intended root, submodule, or example scope.
Use a line-level TFLint annotation when a single finding is exceptional and disabling the rule for the full supported configuration scope would hide unrelated findings. TFLint annotations can suppress issues only in valid, parseable Terraform and only when the rule permits annotations. Read the current TFLint annotation documentation before using one.
# This declaration is consumed after the managed transform runs.
# tflint-ignore: terraform_unused_declarations
avm_azapi_header = join(" ", [for k, v in local.avm_azapi_headers : "${k}=${v}"])Name only the specific rule and explain the reason. Do not use all. Avoid file-level annotations unless the entire file genuinely needs the same exception.
avm lint and inspect the merged-scope result.Never disable a rule merely to make CI pass. Keep exceptions temporary where possible. A scope-wide override does not authorize unrelated violations in that scope; manually review the scope for any additional occurrences.
| File | Scope |
|---|---|
avm.tflint.override.hcl | Root module checks. |
avm.tflint_module.override.hcl | Every direct submodule under modules/*. |
avm.tflint_example.override.hcl | Every direct example under examples/*. |
modules/<name>/avm.tflint.override.hcl | One direct submodule only. |
examples/<name>/avm.tflint.override.hcl | One direct example only. |
Avm.Authoring merges the immutable AVM base configuration first, then the matching repository-wide scope override, then the target-directory override. The target override wins for that direct submodule or example. Nested module and example roots are prohibited, so do not invent override paths below modules/* or examples/*.
Use normal TFLint rule configuration with the current canonical rule name:
# This pattern module does not represent one resource, so RMFR7 does not apply.
rule "avm_output_resource_id_required" {
enabled = false
}AVM plugin rules also accept severity = "error", "warning", or "notice":
# Track legacy interface migration without blocking unrelated maintenance.
rule "avm_interface_lock_deprecated" {
enabled = true
severity = "notice"
}Per-rule severity changes are separate from TFLint's global --minimum-failure-severity process threshold.
For a narrowly approved AzureRM exception, prefer an override of avm_provider_azurerm_disallowed in the narrowest supported scope and list every permitted azurerm_* block in the justification comments with the AzAPI gap and upstream issue or pull request. If the scope contains other AzureRM checks that must remain enforced, use a justified line-level annotation for the exceptional finding instead. Manually verify that no undocumented AzureRM declarations or usages exist.
Ruleset v1.0.0 removed all legacy aliases. Every AVM rule identifier starts with avm_. Old names such as provider_azurerm_disallowed, required_output_rmfr7, resource_types, retry, and timeouts are invalid in current configuration.
This is the current v1.0.0 inventory. Verify it against the live sources above before use.
| Rule | Scope | Default severity |
|---|---|---|
avm_azapi_data_response_export_values_required | All module scopes | Error |
avm_azapi_replace_triggers_refs_valid | All module scopes | Error |
avm_azapi_resource_tags_required | All module scopes | Error |
avm_azapi_response_export_values_required | All module scopes | Error |
avm_interface_customer_managed_key | All module scopes | Error |
avm_interface_diagnostic_settings | All module scopes | Error |
avm_interface_ignore_body_changes | All module scopes | Error |
avm_interface_location | All module scopes | Error |
avm_interface_lock | All module scopes | Error |
avm_interface_lock_deprecated | All module scopes | Notice |
avm_interface_managed_identities | All module scopes | Error |
avm_interface_private_endpoints | All module scopes | Error |
avm_interface_private_endpoints_deprecated | All module scopes | Notice |
avm_interface_private_endpoints_manage_dns_zone_group | All module scopes | Error |
avm_interface_resource_types | All module scopes | Error |
avm_interface_retry | All module scopes | Error |
avm_interface_role_assignments | All module scopes | Error |
avm_interface_role_assignments_deprecated | All module scopes | Notice |
avm_interface_tags | All module scopes | Error |
avm_interface_timeouts | All module scopes | Error |
avm_output_entire_resource_disallowed | Module scopes | Error |
avm_output_resource_id_required | Root module | Error |
avm_provider_azapi_version_constraint | Module scopes | Error |
avm_provider_azurerm_disallowed | Module scopes | Error |
avm_provider_azurerm_version_constraint | Module scopes | Error |
avm_provider_modtm_version_constraint | Module scopes | Error |
avm_terraform_configuration_file_required | Module scopes | Error |
avm_terraform_ignore_changes_unquoted_references | All module scopes | Error |
avm_terraform_literal_heredoc_disallowed | All module scopes | Notice |
avm_terraform_module_source_required | Module scopes | Error |
avm_terraform_provider_block_disallowed | Module scopes | Warning |
avm_terraform_sensitive_variable_default_disallowed | All module scopes | Warning |
The AVM plugin does not duplicate all formatting and Terraform checks:
nullable = true.Run the managed command and address findings from each owner. Do not create an AVM-rule override for a formatting problem owned by MAPOTF.
© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/avm-tf-tflint of Azure/terraform-azurerm-avm-ptn-alz.
Open the folder on GitHubat commit e2a318c
Avm Tf Tflint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Avm Tf Tflint this skillAzure/terraform-azurerm-avm-ptn-alz | 135 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Iac Securityhardw00t/ai-security-arsenal | 105 | — | ~2.4k | Automated safety check: Pass | None | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| TerrasharkLukasNiessen/terrashark | 716 | — | ~843 | Automated safety check: Pass | MIT | |
| Azure Bicep Skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Provider Verificationmondoohq/mql | 412 | — | ~3.7k | Automated safety check: Pass | Custom licence |
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
LukasNiessen/terrashark
Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
mondoohq/mql
Verify mql provider resource/field changes against real cloud infrastructure.
StackGuardian/tirith
Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.
Works with
Categories
A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Avm Tf Tflint is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.
Avm Tf Tflint fits situations like: an AVM Terraform task involves TFLint findings; rule applicability; lint validation; any AVM TFLint rule identifier.
Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-tflint in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-tflint in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a codex`. Or copy the skill folder (.github/skills/avm-tf-tflint in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-tflint in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-tflint, .gemini/skills/avm-tf-tflint, .github/skills/avm-tf-tflint and .opencode/skills/avm-tf-tflint in your project.
SKILL.md names no scripts, command-line tools or credentials: Avm Tf Tflint is instructions for the agent only.
SKILL.md names 2 domains. As links in the text: github.com and azure.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Avm Tf Tflint is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Avm Tf Tflint: Iac Security (hardw00t/ai-security-arsenal, 105 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 716 stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.
Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.