Official agent skill

Avm Tf Tflint

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Tflint

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-tflint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-tflint .claude/skills/avm-tf-tflint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-tflint
GitHub stars
135
Token cost
~2.2k tokens
SKILL.md length
847 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.

  • Works in 4 steps: Read the current AVM TFLint rules and… → Read the current… → Check the latest released ruleset when a… → …
  • An AVM Terraform task involves TFLint findings
  • SKILL.md covers Read current sources first, Run the managed toolchain, Prefer configuration overrides and Override only after…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Avm Tf Tflint is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code and Linting and formatting. It works with Terraform and Microsoft Azure. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • An AVM Terraform task involves TFLint findings
  • Rule applicability
  • Lint validation
  • Any AVM TFLint rule identifier

Example prompts

  • “tflint”
  • “lint failure”
  • “disable rule”
  • “/avm-tf-tflint”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the current AVM TFLint rules and configuration overrides.
  2. Read the current Azure/tflint-ruleset-avm rule inventory.
  3. Check the latest released ruleset when a plugin version or supported option matters.
  4. Fetch the linked AVM specification for the reported rule before changing Terraform.

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl and powershell).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Tflint loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 847 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 847 words, ~2,187 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-tflint/SKILL.md (or your agent's skills folder).
name
avm-tf-tflint
description
Use whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm_* rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.

AVM Terraform TFLint

Use TFLint through Avm.Authoring. Fix violations instead of suppressing them unless the published AVM requirement genuinely does not apply.

Read current sources first

Before diagnosing a finding or changing rule configuration:

  1. Read the current AVM TFLint rules and configuration overrides.
  2. Read the current Azure/tflint-ruleset-avm rule inventory.
  3. Check the latest released ruleset when a plugin version or supported option matters.
  4. Fetch the linked AVM specification for the reported rule before changing Terraform.

The published rules guide controls applicability and the supported override process. The released plugin controls valid rule identifiers and configuration. Do not rely on an older module, cached rule name, or this inventory when a live source differs.

Run the managed toolchain

pwsh
Import-Module Avm.Authoring
avm version
avm lint

If the version gate reports a stale installation, run avm update, re-import the module, and retry. Run avm pre-commit before linting when managed sync or transforms can affect the configuration. Use avm pr-check only after committing the complete worktree because it requires a clean worktree.

Do not approximate the managed configuration with a separately installed TFLint binary, custom plugin setup, Make, Porch, or a container.

Prefer configuration overrides

Use the supported AVM override files by default. They make exceptions visible, reviewable, and consistent across the intended root, submodule, or example scope.

Use a line-level TFLint annotation when a single finding is exceptional and disabling the rule for the full supported configuration scope would hide unrelated findings. TFLint annotations can suppress issues only in valid, parseable Terraform and only when the rule permits annotations. Read the current TFLint annotation documentation before using one.

hcl
# This declaration is consumed after the managed transform runs.
# tflint-ignore: terraform_unused_declarations
avm_azapi_header = join(" ", [for k, v in local.avm_azapi_headers : "${k}=${v}"])

Name only the specific rule and explain the reason. Do not use all. Avoid file-level annotations unless the entire file genuinely needs the same exception.

Override only after investigating

  1. Read the rule guidance and its linked AVM specification.
  2. Confirm the rule applies to the failing root, submodule, or example.
  3. Prefer a compliant code change.
  4. If an exception is justified, decide whether a line-level annotation preserves more coverage than the narrowest supported override file.
  5. Explain why the exception is valid, its exact scope, and any issue or pull request that will remove it.
  6. Re-run avm lint and inspect the merged-scope result.

Never disable a rule merely to make CI pass. Keep exceptions temporary where possible. A scope-wide override does not authorize unrelated violations in that scope; manually review the scope for any additional occurrences.

Supported override files

FileScope
avm.tflint.override.hclRoot module checks.
avm.tflint_module.override.hclEvery direct submodule under modules/*.
avm.tflint_example.override.hclEvery direct example under examples/*.
modules/<name>/avm.tflint.override.hclOne direct submodule only.
examples/<name>/avm.tflint.override.hclOne direct example only.

Avm.Authoring merges the immutable AVM base configuration first, then the matching repository-wide scope override, then the target-directory override. The target override wins for that direct submodule or example. Nested module and example roots are prohibited, so do not invent override paths below modules/* or examples/*.

Use normal TFLint rule configuration with the current canonical rule name:

hcl
# This pattern module does not represent one resource, so RMFR7 does not apply.
rule "avm_output_resource_id_required" {
  enabled = false
}

AVM plugin rules also accept severity = "error", "warning", or "notice":

hcl
# Track legacy interface migration without blocking unrelated maintenance.
rule "avm_interface_lock_deprecated" {
  enabled  = true
  severity = "notice"
}

Per-rule severity changes are separate from TFLint's global --minimum-failure-severity process threshold.

For a narrowly approved AzureRM exception, prefer an override of avm_provider_azurerm_disallowed in the narrowest supported scope and list every permitted azurerm_* block in the justification comments with the AzAPI gap and upstream issue or pull request. If the scope contains other AzureRM checks that must remain enforced, use a justified line-level annotation for the exceptional finding instead. Manually verify that no undocumented AzureRM declarations or usages exist.

Show full SKILL.md (271 more words)Show less

Canonical rule names

Ruleset v1.0.0 removed all legacy aliases. Every AVM rule identifier starts with avm_. Old names such as provider_azurerm_disallowed, required_output_rmfr7, resource_types, retry, and timeouts are invalid in current configuration.

This is the current v1.0.0 inventory. Verify it against the live sources above before use.

RuleScopeDefault severity
avm_azapi_data_response_export_values_requiredAll module scopesError
avm_azapi_replace_triggers_refs_validAll module scopesError
avm_azapi_resource_tags_requiredAll module scopesError
avm_azapi_response_export_values_requiredAll module scopesError
avm_interface_customer_managed_keyAll module scopesError
avm_interface_diagnostic_settingsAll module scopesError
avm_interface_ignore_body_changesAll module scopesError
avm_interface_locationAll module scopesError
avm_interface_lockAll module scopesError
avm_interface_lock_deprecatedAll module scopesNotice
avm_interface_managed_identitiesAll module scopesError
avm_interface_private_endpointsAll module scopesError
avm_interface_private_endpoints_deprecatedAll module scopesNotice
avm_interface_private_endpoints_manage_dns_zone_groupAll module scopesError
avm_interface_resource_typesAll module scopesError
avm_interface_retryAll module scopesError
avm_interface_role_assignmentsAll module scopesError
avm_interface_role_assignments_deprecatedAll module scopesNotice
avm_interface_tagsAll module scopesError
avm_interface_timeoutsAll module scopesError
avm_output_entire_resource_disallowedModule scopesError
avm_output_resource_id_requiredRoot moduleError
avm_provider_azapi_version_constraintModule scopesError
avm_provider_azurerm_disallowedModule scopesError
avm_provider_azurerm_version_constraintModule scopesError
avm_provider_modtm_version_constraintModule scopesError
avm_terraform_configuration_file_requiredModule scopesError
avm_terraform_ignore_changes_unquoted_referencesAll module scopesError
avm_terraform_literal_heredoc_disallowedAll module scopesNotice
avm_terraform_module_source_requiredModule scopesError
avm_terraform_provider_block_disallowedModule scopesWarning
avm_terraform_sensitive_variable_default_disallowedAll module scopesWarning

Understand adjacent tooling

The AVM plugin does not duplicate all formatting and Terraform checks:

  • MAPOTF owns deterministic ordering, file placement transforms, formatting, and removal of redundant explicit nullable = true.
  • The standard Terraform TFLint plugin validates Terraform and provider requirement declarations.
  • The AVM ruleset adds AVM-specific specification checks.

Run the managed command and address findings from each owner. Do not create an AVM-rule override for a formatting problem owned by MAPOTF.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-tflint of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Tflint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Tflint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Tflint this skillAzure/terraform-azurerm-avm-ptn-alz135—~2.2kAutomated safety check: PassMIT
Iac Securityhardw00t/ai-security-arsenal105—~2.4kAutomated safety check: PassNone
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark716—~843Automated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Provider Verificationmondoohq/mql412—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    105 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    716 GitHub stars~843 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    412 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Avm Tf Tflint

What does Avm Tf Tflint do?

A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Avm Tf Tflint is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.

When should I use Avm Tf Tflint?

Avm Tf Tflint fits situations like: an AVM Terraform task involves TFLint findings; rule applicability; lint validation; any AVM TFLint rule identifier.

How do I install Avm Tf Tflint in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-tflint in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-tflint in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Tflint in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a codex`. Or copy the skill folder (.github/skills/avm-tf-tflint in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-tflint in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Tflint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-tflint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-tflint, .gemini/skills/avm-tf-tflint, .github/skills/avm-tf-tflint and .opencode/skills/avm-tf-tflint in your project.

What does Avm Tf Tflint need to run?

SKILL.md names no scripts, command-line tools or credentials: Avm Tf Tflint is instructions for the agent only.

Does Avm Tf Tflint access the network?

SKILL.md names 2 domains. As links in the text: github.com and azure.github.io. This is read from the text; nothing was executed.

Is Avm Tf Tflint safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Tflint use?

Avm Tf Tflint is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Tflint use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Tflint?

Skills that share tags, products or a category with Avm Tf Tflint: Iac Security (hardw00t/ai-security-arsenal, 105 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 716 stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Tflint?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.