Official agent skill

Datadog Data Source Generator

by DataDog in DataDog/terraform-provider-datadog

Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

OfficialMPL-2.0Auto-check passedDevOps & Cloud

Install Datadog Data Source Generator

skills CLI
$ npx skills add DataDog/terraform-provider-datadog --skill generate-datadog-datasource -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/terraform-provider-datadog generate-datadog-datasource --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/terraform-provider-datadog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/generate-datadog-datasource .claude/skills/generate-datadog-datasource && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generate-datadog-datasource
GitHub stars
468
Token cost
~2.7k tokens
SKILL.md length
1,251 words
Files
7 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MPL-2.0

At a glance

Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

  • Works in 3 steps: Input → Generation → PR
  • Generating a Datadog data source for a given OpenAPI operation
  • SKILL.md covers Operating principles — run it…, The one rule that overrides…, Phase 1 — Input and Phase 2 — Generation, plus 4 more sections
  • Calls make and gh

What it does

The skill runs three phases. Input collects the read group of operation IDs, the artifact name, cardinality, description and overwrite target. Generation builds an annotated OpenAPI slice with slice_and_annotate.py, runs tfgen on it, runs make docs and build, and commits onto a new branch. The PR phase does a quick runtime-risk scan, drafts the standard PR body with disclaimers and a testing guide, and opens the PR with gh.

The operating principles keep it fast: trust the generator, never fix on failure but quote the error verbatim and stop, and keep analysis light. A firm rule bars calling code verified unless a cassette actually replayed green, since a clean build only shows the code was generated and compiles. Reference files cover collecting inputs, running tfgen, slicing and annotating, the PR body template, risk heuristics and the testing guide.

When your agent uses it

  • Generating a Datadog data source for a given OpenAPI operation
  • Opening a review-ready PR for a generated data source
  • Writing cassette or acceptance-test instructions for a generated data source

Example prompts

  • “Generate a Datadog data source for the list monitors operation and open a PR.”
  • “Run tfgen on this OpenAPI slice and give me the PR body with a testing guide.”
  • “Evaluate the generated data source against the goldens and flag runtime risks.”

Requirements

  • git and an authenticated gh CLI
  • Python 3 with PyYAML
  • A checkout of the terraform-provider-datadog repository
  • Network access to the Datadog v2 OpenAPI spec
  • Compatibility (from SKILL.md): Requires `git`, `gh` (authenticated), Python 3 + PyYAML, a checkout of the terraform-provider-datadog repo, and network access to the full Datadog v2 OpenAPI spec (curled from upstream by default; overridable via `--spec` or `$DATADOG_OPENAPI_V2_SPEC`).

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Input
  2. Generation
  3. PR

What it can do on your machine

Read from SKILL.md and the folder at commit ca0801d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires `git`, `gh` (authenticated), Python 3 + PyYAML, a checkout of the terraform-provider-datadog repo, and network access to the full Datadog v2 OpenAPI spec (curled from upstream by default; overridable via `--spec` or `$DATADOG_OPENAPI_V2_SPEC`).

    From compatibility in the SKILL.md frontmatter.

Context cost

Datadog Data Source Generator loads about 2.7k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 231 tokens; SKILL.md has 1,251 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~231
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DataDog/terraform-provider-datadog at commit ca0801d, republished under its MPL-2.0 licence (© DataDog). 1,251 words, ~2,743 tokens.

Download SKILL.mdSave it as .claude/skills/generate-datadog-datasource/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
generate-datadog-datasource
description
Generate a Datadog Terraform provider data source end to end and open a review-ready GitHub PR for it. Runs in three phases: (1) Input — collect the read group (operationIds), artifact name, cardinality, description, and overwrite target; (2) Generation — build an annotated OpenAPI slice with slice_and_annotate.py, run tfgen on it, run make docs/build, and commit onto a new branch; (3) PR — a quick runtime-risk scan (trusting the generator for correctness), draft the standard PR body with disclaimers + testing guide, and open the PR with `gh`. Use this skill whenever the user wants to generate a Datadog data source, mentions tfgen / generator-v2, slice_and_annotate, an OpenAPI operation they want a data source for, opening a PR for a generated data source, evaluating generated code against goldens, or writing cassette / acceptance-test instructions — even if they don't say "skill".
compatibility
Requires `git`, `gh` (authenticated), Python 3 + PyYAML, a checkout of the terraform-provider-datadog repo, and network access to the full Datadog v2 OpenAPI spec (curled from upstream by default; overridable via `--spec` or `$DATADOG_OPENAPI_V2_SPEC`).

Generate a Datadog data source (input → generation → PR)

This skill takes a Datadog v2 OpenAPI operation from nothing to a review-ready PR. It owns the whole flow — the earlier version assumed tfgen had already generated and committed; this version runs generation itself, so it also owns branching and committing.

Phase 1: INPUT        Phase 2: GENERATION                    Phase 3: PR
collect params  ──▶   slice_and_annotate.py → slice     ──▶  classify scenario
(routes, name,        tfgen generate → .go + test             evaluate vs goldens + risks
 cardinality,         make docs / make build                  draft PR body
 description,         branch off master + commit               open PR with gh
 overwrite)           (gate on the RunReport first)            report back

Each phase has its own reference subdirectory under references/. Read the reference for a phase before running it.

Operating principles — run it fast and hands-off

tfgen is deterministic and well-tested. This skill is a thin wrapper around it, not an audit. Three rules keep runs fast and honest:

  1. Trust the generator. If tfgen produced the files and make build passed, treat the output as correct. Do not re-derive its decisions, re-verify field-by-field, or second-guess the scenario it emitted. Report what happened — don't prove the code right.
  2. Never fix — report and stop. On ANY failure (spec/annotation error, generation failure, make build/make docs failure, or a red CI check) do not edit the spec, patch the generated code, retry, or work around it. Quote the error verbatim, say plainly why the data source could not be generated, and stop. For a failed run, that report is the deliverable.
  3. Keep analysis light. The only judgment that matters is a quick scan for material runtime risks (references/pr/risk-heuristics.md) — minutes, not a line-by-line review, and not a golden diff. If nothing clearly applies, say so and move on.

The one rule that overrides everything: never overclaim "verified"

A green RunReport and a clean build prove only that code was generated and compiles — not that it works at runtime. A plural data source has built and reported created cleanly yet returned 0 rows live (read-after-write lag / silent-empty trap; see references/pr/risk-heuristics.md). So:

  • Only use "verified", "working", "confirmed", or "replays green" if a cassette actually replayed green.
  • If generation/build succeeded but no cassette has replayed, say exactly that: "generated and builds cleanly; runtime behavior not yet verified — see testing guide."
  • When in doubt, describe what was checked, not what you assume.

This is the single most common way to write a misleading PR here. Guard against it in every section you draft, and never let the confidence of having generated the code leak into runtime claims.


Phase 1 — Input

Goal: produce a complete, validated parameter set for slice_and_annotate.py. Nothing is generated in this phase — you are only deciding what to generate.

Collect, confirming each with the user:

  • Spec path — default: curl the upstream v2 spec to a temp file (see references/input/collecting-inputs.md); an explicit path or $DATADOG_OPENAPI_V2_SPEC overrides. A local copy must exist before you can discover routes.
  • Read group (routes) — the operationIds. If the user names a resource/service and a spec is available, inspect it and propose candidate GET routes; otherwise take operationIds directly. Validate every operationId against the spec.
  • Cardinality + scenario — singular (by-id / both / search-only) vs plural, derived from which GETs exist and what the user wants.
  • Artifact name — default derived from the resource (snake_case, no datadog_ prefix); validate ^[a-z][a-z0-9_]*$, ≤64.
  • TF description — default Use this data source to retrieve information about an existing Datadog <thing>. (plural: …existing Datadog <thing>s.); only ask if they want a custom one.
  • Overwrite — auto-detect whether a hand-written datadog_<name> data source already exists; if so, find its constructor and ask whether to retire it (--overwrites). Otherwise additive.

End the phase by echoing the full parameter set back and getting a go-ahead.

Details: references/input/collecting-inputs.md.


Phase 2 — Generation

Goal: turn the parameter set into committed generated files on a fresh branch. Do not open a PR here.

  1. Preconditions. gh auth status authenticated. If HEAD is master, that's fine — this phase creates the branch. Ensure bin/tfgen exists (make tfgen-build if not).
  2. Build the slice. Call slice_and_annotate.py with the phase-1 params; capture the printed slice path (stdout is only the path). See references/generation/slice-and-annotate.md.
  3. Generate. Run tfgen generate --spec "$SLICE" --report -, capturing the RunReport JSON. See references/generation/running-tfgen.md.
  4. Gate on the report — before committing. Stop if summary.failed > 0 or any diagnostics[].severity == "error". Quote the failing artifact + diagnostics verbatim, say plainly why it couldn't be generated, and stop — do not edit the spec, retry, or fix anything (principle 2). Leave the working tree uncommitted. That report is the deliverable; nothing is committed. warning/info do not gate — carry them into the PR risk section.
  5. Docs + build. Run make docs (creates docs/data-sources/<name>.md) and make build to confirm it compiles. Use make targets, never raw go. If either fails, quote the output and stop (principle 2) — do not attempt to fix the generated code.
  6. Branch + commit. Create the branch off master and commit the generated .go, test, and docs files. Carry forward to Phase 3: the RunReport, the known scenario/cardinality, the slice path, and the branch name.

Details: references/generation/slice-and-annotate.md, references/generation/running-tfgen.md.


Show full SKILL.md (466 more words)Show less

Phase 3 — PR

Goal: turn the committed branch into a review-ready PR. The scenario and RunReport are already known from Phase 2 — do not re-derive them; just carry them in.

  1. Quick risk scan. Skim references/pr/risk-heuristics.md and flag only the risks that clearly apply to this endpoint (e.g. paginated plural, sensitive detail-only fields, path-nested by-id). This is a fast pass, not a code audit — trust the generator for correctness. If nothing material jumps out, say so and move on.
  2. (Optional) Golden sanity-check. Only if a specific risk needs confirming, open the matching emit golden under .generator-v2/internal/testdata/emit/ (the scenario template) to check that one doubt. Otherwise skip — do not diff the generated code against goldens by default.
  3. Draft the PR body. Use references/pr/pr-body-template.md exactly: project-context disclaimer first, test-scaffold disclaimer second, verification disclaimer third, then a prominent risk callout if any material risk was found, then the docs callout if docs/data-sources/<name>.md is absent, then the body. Populate "Generated" from artifacts[].{name,status,path}.
  4. CI-required metadata (all three, or CI never goes green). Verification disclaimer in the body; title [<service>] Add datadog_<name> data source (derive <service> from the spec tag; ask if unsure — a wrong prefix fails CI); changelog/feature label.
  5. Open the PR. Push the branch, then gh pr create. Opening a PR publishes on the user's behalf — confirm the drafted title, body, and label with the user first.
  6. Checks + report back. After the PR exists, read gh pr checks; for a failing check, gh run view <run-id> --log-failed and report which check failed with its output quoted — do not attempt to fix it (principle 2). Report the PR URL, the gate result, the risks flagged (and why), and the build/check status — precise about verification per the top rule.

Details: references/pr/risk-heuristics.md, references/pr/pr-body-template.md, references/pr/testing-guide.md.


References

  • references/input/collecting-inputs.md — Phase 1: the parameter set, spec resolution, route discovery, scenario/cardinality decision, overwrite auto-detect.
  • references/generation/slice-and-annotate.md — Phase 2: how to call slice_and_annotate.py and how the annotation works.
  • references/generation/running-tfgen.md — Phase 2: build tfgen, generate, gate on the report, make docs/build, branch + commit.
  • references/pr/risk-heuristics.md — Phase 3: scenario-specific runtime pitfalls. Read every run.
  • references/pr/pr-body-template.md — Phase 3: the exact PR body + footer.
  • references/pr/testing-guide.md — Phase 3: Frog-org record/replay + cassette instructions.

How the generated data source is registered

tfgen owns datadog/fwprovider/datasources_generated.go: every run rewrites its generatedDatasources slice from the set of data sources produced. framework_provider.go appends that slice alongside the hand-written Datasources, so additive generation is wired up without editing framework_provider.go. framework_provider.go is edited only in the overwrite case — to remove the retired hand-written constructor from its Datasources slice. Reflect this accurately in the PR body; do not repeat the older "hand-wired into framework_provider.go" phrasing.

Scope note

This is the locally-runnable version of this skill, in active development. Expect rough edges. Do not put any "demo/crude/in-development" language into an actual PR except the single footer callout defined in the template.

© DataDog, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .claude/skills/generate-datadog-datasource of DataDog/terraform-provider-datadog.

  • SKILL.md
  • references/generation/running-tfgen.md
  • references/generation/slice-and-annotate.md
  • references/input/collecting-inputs.md
  • references/pr/pr-body-template.md
  • references/pr/risk-heuristics.md
  • references/pr/testing-guide.md

Open the folder on GitHubat commit ca0801d

Compare with similar skills

Datadog Data Source Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Datadog Data Source Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Datadog Data Source Generator this skillDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0
Aliyun Swas Managecinience/alicloud-skills3971 repos~1.9kAutomated safety check: PassMIT
B24phpsdk Maintainerbitrix24/b24phpsdk102—~10kAutomated safety check: NotesMIT
PR Reviewansible-collections/community.postgresql144—~1.6kAutomated safety check: PassCustom licence
Neo4j Aura Provisioning Skillneo4j-contrib/neo4j-skills1141 repos~3.7kAutomated safety check: NotesMIT
Admingrafana/skills279—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Aliyun Swas Manage

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Simple Application Server (SWAS OpenAPI 2020-06-01) resources end-to-end, including querying instances, starting/stopping/rebooting, executing…

    397 GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • B24phpsdk Maintainer

    bitrix24/b24phpsdk

    A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…

    102 GitHub stars~10k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • PR Review

    ansible-collections/community.postgresql

    Reviews pull requests and code changes in this Ansible collection against project standards and the Ansible Collection Review Checklist.

    144 GitHub stars~1.6k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub starsUsed in 1 repo~3.7k tokens
    DevOps & CloudAuto-check: notes
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    279 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Submits code changes as a GitHub pull request through an isolated Git clone, reusing or creating your fork and pushing only after you confirm the real diff.

    12k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check: notes

More from DataDog/terraform-provider-datadog

  • Datadog Terraform Provider Test Runner

    DataDog/terraform-provider-datadog

    Official

    Runs Datadog Terraform provider acceptance tests in none, true or false record modes, then saves trimmed output and pass, fail and skip counts to a timestamped file.

    468 GitHub stars~949 tokensUpdated yesterday
    Auto-check passed
  • Fix Broken Datadog Provider Tests

    DataDog/terraform-provider-datadog

    Official

    Runs an end-to-end workflow to diagnose, reproduce, fix and validate a failing integration test in the Datadog Terraform provider, ending with a draft PR.

    468 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check: notes

Questions about Datadog Data Source Generator

What does Datadog Data Source Generator do?

Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide. The skill runs three phases. Input collects the read group of operation IDs, the artifact name, cardinality, description and overwrite target.

When should I use Datadog Data Source Generator?

Datadog Data Source Generator fits situations like: generating a Datadog data source for a given OpenAPI operation; opening a review-ready PR for a generated data source; writing cassette or acceptance-test instructions for a generated data source.

How do I install Datadog Data Source Generator in Claude Code?

Run `npx skills add DataDog/terraform-provider-datadog --skill generate-datadog-datasource -a claude-code`. Or copy the skill folder (.claude/skills/generate-datadog-datasource in DataDog/terraform-provider-datadog) into .claude/skills/generate-datadog-datasource in your project. Claude Code loads it when a task matches its description.

How do I install Datadog Data Source Generator in Codex?

Run `npx skills add DataDog/terraform-provider-datadog --skill generate-datadog-datasource -a codex`. Or copy the skill folder (.claude/skills/generate-datadog-datasource in DataDog/terraform-provider-datadog) into .agents/skills/generate-datadog-datasource in your project. Codex loads it when a task matches its description.

Can I use Datadog Data Source Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/terraform-provider-datadog --skill generate-datadog-datasource -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generate-datadog-datasource, .gemini/skills/generate-datadog-datasource, .github/skills/generate-datadog-datasource and .opencode/skills/generate-datadog-datasource in your project.

What does Datadog Data Source Generator need to run?

Going by SKILL.md and its folder, Datadog Data Source Generator needs the command-line tools its instructions call (make and gh). Our summary lists: git and an authenticated gh CLI; Python 3 with PyYAML; A checkout of the terraform-provider-datadog repository; Network access to the Datadog v2 OpenAPI spec. Compatibility (from SKILL.md): Requires `git`, `gh` (authenticated), Python 3 + PyYAML, a checkout of the terraform-provider-datadog repo, and network access to the full Datadog v2 OpenAPI spec (curled from upstream by default; overridable via `--spec` or `$DATADOG_OPENAPI_V2_SPEC`)..

Does Datadog Data Source Generator access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Datadog Data Source Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Datadog Data Source Generator use?

Datadog Data Source Generator is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Datadog Data Source Generator use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.5k tokens, read only when the agent opens those files.

What are the alternatives to Datadog Data Source Generator?

Skills that share tags, products or a category with Datadog Data Source Generator: Aliyun Swas Manage (cinience/alicloud-skills, 397 stars), B24phpsdk Maintainer (bitrix24/b24phpsdk, 102 stars), PR Review (ansible-collections/community.postgresql, 144 stars) and Neo4j Aura Provisioning Skill (neo4j-contrib/neo4j-skills, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Datadog Data Source Generator?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/terraform-provider-datadog, which has 468 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: DataDog/terraform-provider-datadog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.