Official agent skill

Write Only Attributes

by dbt-labs in dbt-labs/terraform-provider-dbtcloud

A skill your agent uses when adding, changing or fixing write-only (wo) attributes, woversion fields or any secret attribute (password, token, private key) on a resource, data source or semantic…

OfficialMITAuto-check passedDevOps & Cloud

Install Write Only Attributes

skills CLI
$ npx skills add dbt-labs/terraform-provider-dbtcloud --skill write-only-attributes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dbt-labs/terraform-provider-dbtcloud write-only-attributes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dbt-labs/terraform-provider-dbtcloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/write-only-attributes .claude/skills/write-only-attributes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
write-only-attributes
GitHub stars
117
Token cost
~1.1k tokens
SKILL.md length
546 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding, changing or fixing write-only (wo) attributes, woversion fields or any secret attribute (password, token, private key) on a resource, data source or semantic…

  • Fixing write-only (wo) attributes
  • SKILL.md covers Schema, Create and Update and Testing
  • Calls go
  • Woversion fields

What it does

Write Only Attributes is an agent skill from dbt-labs/terraform-provider-dbtcloud, published by the product's own GitHub organization. Use when adding, changing or fixing write-only (wo) attributes, woversion fields or any secret attribute (password, token, private key) on a resource, data source or semantic layer credential in this provider. Covers schema, Create/Update, validators and testing, and the bugs seen before.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code and Data pipelines and ETL. It works with dbt and Terraform. The repository describes itself as: dbt Cloud Terraform Provider. The licence is MIT.

When your agent uses it

  • Fixing write-only (wo) attributes
  • Woversion fields
  • Any secret attribute (password
  • Private key) on a resource

Example prompts

  • “/write-only-attributes”

What it can do on your machine

Read from SKILL.md and the folder at commit d235acd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Write Only Attributes loads about 1.1k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 546 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dbt-labs/terraform-provider-dbtcloud at commit d235acd, republished under its MIT licence (© dbt-labs). 546 words, ~1,109 tokens.

Download SKILL.mdSave it as .claude/skills/write-only-attributes/SKILL.md (or your agent's skills folder).
name
write-only-attributes
description
Use when adding, changing or fixing write-only (`_wo`) attributes, `*_wo_version` fields or any secret attribute (password, token, private key) on a resource, data source or semantic layer credential in this provider. Covers schema, Create/Update, validators and testing, and the bugs seen before.

Write-only (_wo) attributes

Secrets can be set with a write-only attribute (token_wo, password_wo, private_key_wo, ...) so they never reach the Terraform state. Write-only attributes need Terraform >= 1.11. Most existing bugs in this area come from copying a neighbouring resource without knowing the points below. The reference implementation is pkg/framework/objects/snowflake_credential.

Schema

  • Declare the pair <name>_wo (Optional, WriteOnly: true) and <name>_wo_version (Optional, Int64). The version is how Terraform notices a rotation, because the value itself is never stored.
  • On the plain attribute, add stringvalidator.ConflictsWith(path.MatchRelative().AtParent().AtName("<name>_wo")) and helper.PreferWriteOnlyAttributeValidator{WriteOnlyAttributeName: "<name>_wo"}.
  • Always use relative paths (MatchRelative().AtParent()), never path.MatchRoot. The credential schemas are reused nested under credential by the semantic layer resources, and an absolute path then fails with Invalid Path Expression for Schema (#712, #710). The same goes for stringvalidator.PreferWriteOnlyAttribute, use the helper in pkg/helper instead.
  • A computed id needs UseStateForUnknown(), otherwise every plan shows an in-place update (#719).
  • If the data source shares its model with the resource, the _wo attributes have to exist in the data source schema too (as Computed), otherwise reading the config or setting the state fails on the missing field.
  • Any validator that requires the plain attribute (for example "private_key must be set") has to accept the write-only one as well.

Create and Update

  • Write-only values are null in the plan and the state. Read them from req.Config, not req.Plan, and resolve them with helper.ResolveWriteOnlyString(config.<Name>Wo, plan.<Name>). Only reading the plan sends an empty secret to the API, and the apply still succeeds (#732).
  • Decide whether to send the secret with <name>_wo_version (and the plain attribute) changing between state and plan, never with the _wo value.
  • Set the state from the plan, not from the API response. The API never echoes secrets, so writing the response back into the secret fields gives inconsistent values for sensitive attribute or an empty value (#732). Keep <name>_wo null in the state and carry <name>_wo_version over from the plan.
  • Do not send a partial update that blanks the secret. Some endpoints replace the whole record, so an empty secret clears what is stored and can drop related links such as service token mappings.
  • After import the version is null, so the first plan with <name>_wo_version set shows an update. That is expected, add <name>_wo_version to ImportStateVerifyIgnore.
Show full SKILL.md (176 more words)Show less

Testing

  • Acceptance tests that use _wo attributes must be guarded with TerraformVersionChecks: []tfversion.TerraformVersionCheck{tfversion.SkipBelow(tfversion.Version1_11_0)}. If the Terraform on your PATH is older, install a newer one (for example tenv tf install 1.12.2) and run with TF_ACC_TERRAFORM_PATH=<path to the binary>. Otherwise the tests are skipped and prove nothing.
  • Add an offline test that sets the plain secret and runs PlanOnly against a mock server, to catch validator path errors. The validators attached to the plain attribute only resolve their _wo sibling when the plain attribute has a value. See pkg/framework/objects/semantic_layer_credential/snowflake_sl_credential_unit_test.go.
  • Add a test with testhelpers.SetupMockServer that applies with the _wo attribute and asserts on the captured request payload (create, then update after bumping the version). Checking the state is not enough: the state is empty either way, which is how #732 went unnoticed for days. Break the resolver temporarily to confirm that the test fails.
  • The mock responses must return nullable fields as explicit null, like the real API, otherwise nullable.MustGet() panics when the response is read.
  • Regenerate the docs with go generate . and add a .changes/unreleased entry.

© dbt-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/write-only-attributes of dbt-labs/terraform-provider-dbtcloud.

Open the folder on GitHubat commit d235acd

Compare with similar skills

Write Only Attributes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Write Only Attributes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Write Only Attributes this skilldbt-labs/terraform-provider-dbtcloud117—~1.1kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Review Helpershashicorp/terraform-provider-aws11k—~978Automated safety check: PassMPL-2.0

Similar skills

  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Review Helpers

    hashicorp/terraform-provider-aws

    Official

    Review Terraform AWS Provider helper code: finders, status functions, waiters, sweepers, data sources, and list resources.

    11k GitHub stars~978 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed

More from dbt-labs/terraform-provider-dbtcloud

  • Bug Fixer

    dbt-labs/terraform-provider-dbtcloud

    Official

    Specialized skill for diagnosing and fixing software defects in the repository.

    117 GitHub stars~269 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Write Only Attributes

What does Write Only Attributes do?

A skill your agent uses when adding, changing or fixing write-only (wo) attributes, woversion fields or any secret attribute (password, token, private key) on a resource, data source or semantic…. Write Only Attributes is an agent skill from dbt-labs/terraform-provider-dbtcloud, published by the product's own GitHub organization. Use when adding, changing or fixing write-only (wo) attributes, woversion fields or any secret attribute (password, token, private key) on a resource, data source or semantic layer credential in this provider.

When should I use Write Only Attributes?

Write Only Attributes fits situations like: fixing write-only (wo) attributes; woversion fields; any secret attribute (password; private key) on a resource.

How do I install Write Only Attributes in Claude Code?

Run `npx skills add dbt-labs/terraform-provider-dbtcloud --skill write-only-attributes -a claude-code`. Or copy the skill folder (.agents/skills/write-only-attributes in dbt-labs/terraform-provider-dbtcloud) into .claude/skills/write-only-attributes in your project. Claude Code loads it when a task matches its description.

How do I install Write Only Attributes in Codex?

Run `npx skills add dbt-labs/terraform-provider-dbtcloud --skill write-only-attributes -a codex`. Or copy the skill folder (.agents/skills/write-only-attributes in dbt-labs/terraform-provider-dbtcloud) into .agents/skills/write-only-attributes in your project. Codex loads it when a task matches its description.

Can I use Write Only Attributes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dbt-labs/terraform-provider-dbtcloud --skill write-only-attributes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/write-only-attributes, .gemini/skills/write-only-attributes, .github/skills/write-only-attributes and .opencode/skills/write-only-attributes in your project.

What does Write Only Attributes need to run?

Going by SKILL.md and its folder, Write Only Attributes needs the command-line tools its instructions call (go).

Does Write Only Attributes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Write Only Attributes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Write Only Attributes use?

Write Only Attributes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Write Only Attributes use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Write Only Attributes?

Skills that share tags, products or a category with Write Only Attributes: Review Docs (hashicorp/terraform-provider-aws, 11k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Cloudflare (hodgef/apiker, 127 stars) and Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Write Only Attributes?

dbt-labs (a GitHub organization, an official publisher) maintains it in dbt-labs/terraform-provider-dbtcloud, which has 117 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: dbt-labs/terraform-provider-dbtcloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.