Agent skill

Atmos Lint

by cloudposse in cloudposse/atmos

Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

Apache-2.0Auto-check passedDevelopment

Install Atmos Lint

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-lint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-lint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-lint .claude/skills/atmos-lint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-lint
GitHub stars
1.4k
Token cost
~1.1k tokens
SKILL.md length
406 words
Files
2 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

  • Works in 4 steps: Component directory → Terraform components base path… → Git repository root → …
  • Documenting Terraform/OpenTofu linting in an Atmos project
  • SKILL.md covers Choose an execution mode, TFLint config discovery, Hooks and CI and Rules and TFLint capabilities
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Atmos Lint is an agent skill from cloudposse/atmos. Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings. Use when configuring, running, debugging, or documenting Terraform/OpenTofu linting in an Atmos project.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/tflint.md`).

It sits in Development, covering Linting and formatting and Infrastructure as code. It works with Terraform. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Documenting Terraform/OpenTofu linting in an Atmos project
  • Tasks that involve Linting and formatting
  • Tasks that involve Infrastructure as code

Example prompts

  • “Use the atmos-lint skill to atmo Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain…”
  • “/atmos-lint”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Component directory
  2. Terraform components base path (components.terraform.base_path)
  3. Git repository root
  4. components.terraform.lint.config (an absolute path or a path relative to the Atmos base path)

What it can do on your machine

Read from SKILL.md and the folder at commit fbae93f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Lint loads about 1.1k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 406 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit fbae93f, republished under its Apache-2.0 licence (© cloudposse). 406 words, ~1,096 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-lint/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
atmos-lint
description
Atmos Terraform linting with TFLint: standalone `atmos terraform lint`, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings. Use when configuring, running, debugging, or documenting Terraform/OpenTofu linting in an Atmos project.
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
ci-automation

Atmos Linting

Use this skill to design or operate Terraform/OpenTofu linting in Atmos. Prefer the native atmos terraform lint command for deliberate lint runs and the tflint hook kind for linting as part of a Terraform lifecycle.

Choose an execution mode

NeedUse
Check one component or every component without plan/applyatmos terraform lint
Check only changed component sourcesatmos terraform lint --affected
Enforce lint before or after a Terraform actionkind: tflint hook
Run a provider-plugin initialization command or a bespoke scriptkind: command hook or workflow step
shell
# All Terraform component directories, once each (default)
atmos terraform lint
atmos terraform lint --all

# A component; Atmos selects a stack context deterministically when needed
atmos terraform lint vpc
atmos terraform lint vpc --stack test

# Changed Terraform components only
atmos terraform lint --affected

Atmos resolves the selected component instance before linting. Declare tflint under that component's dependencies.tools to pin the binary version; Atmos installs it and supplies its PATH for that lint execution. A component used by multiple stacks is linted once, with a deterministic stack context used only to resolve its settings and toolchain.

yaml
components:
  terraform:
    vpc:
      dependencies:
        tools:
          tflint: "0.59.1"

Do not use atmos toolchain install as a prerequisite for normal component linting when dependencies.tools declares TFLint. Use it only to warm a cache or troubleshoot an interactive shell. For precedence of tool declarations, load atmos-toolchain.

TFLint config discovery

When no hook or workflow explicitly passes --config, Atmos finds .tflint.hcl in this order. The most-specific existing path wins:

  1. Component directory
  2. Terraform components base path (components.terraform.base_path)
  3. Git repository root
  4. components.terraform.lint.config (an absolute path or a path relative to the Atmos base path)

Use the explicit lint.config setting for a nonstandard shared config path:

yaml
components:
  terraform:
    lint:
      config: config/tflint/company.hcl

The tflint hook and TFLint workflow step use the same discovery. An explicit --config in their args is intentional and overrides discovery.

Show full SKILL.md (147 more words)Show less

Hooks and CI

Use a component hook when lint must be enforced for normal Terraform commands. Choose the earliest event that gives the desired feedback; static TFLint checks usually belong before init or plan.

yaml
components:
  terraform:
    vpc:
      dependencies:
        tools:
          tflint: "0.59.1"
      hooks:
        lint:
          events:
            - before.terraform.plan
          kind: tflint
          on_failure: fail

The built-in hook runs TFLint with --chdir=$ATMOS_COMPONENT_PATH and --format=sarif. Its default on_failure: warn reports findings without blocking the Terraform command; set on_failure: fail to make lint gating. SARIF is captured from stdout and can render terminal summaries, CI annotations, and code-scanning results.

Use a kind: command hook for provider plugin initialization when required:

yaml
hooks:
  tflint-init:
    events:
      - before.terraform.plan
    kind: command
    command: tflint --chdir=$ATMOS_COMPONENT_PATH --init

Keep initialization and lint separate so its network/plugin behavior is clear. Load atmos-hooks for hook inheritance, conditions, and failure handling; load atmos-ci for CI integration.

Rules and TFLint capabilities

Read references/tflint.md before changing rules, adding provider plugins, or selecting TFLint flags. Preserve an existing project's config style and run the exact component or --affected selection that verifies the intended scope.

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in agent-skills/skills/atmos-lint of cloudposse/atmos.

  • SKILL.md
  • references/tflint.md

Open the folder on GitHubat commit fbae93f

Compare with similar skills

Atmos Lint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Lint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Lint this skillcloudposse/atmos1.4k—~1.1kAutomated safety check: PassApache-2.0
Iac Securityhardw00t/ai-security-arsenal104—~2.4kAutomated safety check: PassNone
Avm Tf TflintAzure/terraform-azurerm-avm-ptn-alz135—~2.2kAutomated safety check: PassMIT
Smt E2E Dataflow DebuggingGoogleCloudPlatform/DataflowTemplates1.3k—~1.8kAutomated safety check: PassApache-2.0
Review PRhashicorp/terraform-provider-aws11k—~1.1kAutomated safety check: PassMPL-2.0
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    104 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Avm Tf Tflint

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation.

    135 GitHub stars~2.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Smt E2E Dataflow Debugging

    GoogleCloudPlatform/DataflowTemplates

    Debugs logical errors and data discrepancies in Dataflow templates by launching jobs via Terraform and comparing source (e.g.

    1.3k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Review PR

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider pull request for correctness and conventions.

    11k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Azure Diagrams

    cmb211087/azure-diagrams-skill

    Comprehensive technical diagramming toolkit for solutions architects, presales, and developers.

    150 GitHub stars~4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Roadmap

    cloudposse/atmos

    Maintain and update the Atmos roadmap page (website/src/data/roadmap.js): milestone/initiative/quarter schema, progress-percentage math, the curated featured[] cap (max 6, never auto-modified), and…

    1.4k GitHub stars~2.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Atmos Lint

What does Atmos Lint do?

Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings. Atmos Lint is an agent skill from cloudposse/atmos. Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

When should I use Atmos Lint?

Atmos Lint fits situations like: documenting Terraform/OpenTofu linting in an Atmos project; tasks that involve Linting and formatting; tasks that involve Infrastructure as code.

How do I install Atmos Lint in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-lint -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-lint in cloudposse/atmos) into .claude/skills/atmos-lint in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Lint in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-lint -a codex`. Or copy the skill folder (agent-skills/skills/atmos-lint in cloudposse/atmos) into .agents/skills/atmos-lint in your project. Codex loads it when a task matches its description.

Can I use Atmos Lint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-lint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-lint, .gemini/skills/atmos-lint, .github/skills/atmos-lint and .opencode/skills/atmos-lint in your project.

What does Atmos Lint need to run?

SKILL.md names no scripts, command-line tools or credentials: Atmos Lint is instructions for the agent only.

Does Atmos Lint access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Atmos Lint safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Lint use?

Atmos Lint is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Lint use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 782 tokens, read only when the agent opens those files.

What are the alternatives to Atmos Lint?

Skills that share tags, products or a category with Atmos Lint: Iac Security (hardw00t/ai-security-arsenal, 104 stars), Avm Tf Tflint (Azure/terraform-azurerm-avm-ptn-alz, 135 stars), Smt E2E Dataflow Debugging (GoogleCloudPlatform/DataflowTemplates, 1.3k stars) and Review PR (hashicorp/terraform-provider-aws, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Lint?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,398 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 9, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.