Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add EliasOulkadi/shokunin --skill terraform -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install EliasOulkadi/shokunin terraform --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/terraform .claude/skills/terraform && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .claude/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraformType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add EliasOulkadi/shokunin --skill terraform -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install EliasOulkadi/shokunin terraform --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.pack/skills/terraform .agents/skills/terraform && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .agents/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EliasOulkadi/shokunin --skill terraform -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install EliasOulkadi/shokunin terraform --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.pack/skills/terraform .cursor/skills/terraform && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .cursor/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/EliasOulkadi/shokunin.git --path .pack/skills/terraform--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add EliasOulkadi/shokunin --skill terraform -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install EliasOulkadi/shokunin terraform --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.pack/skills/terraform .gemini/skills/terraform && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .gemini/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install EliasOulkadi/shokunin terraformInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add EliasOulkadi/shokunin --skill terraform -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .github/skills && cp -r skills-src/.pack/skills/terraform .github/skills/terraform && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .github/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EliasOulkadi/shokunin --skill terraform -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install EliasOulkadi/shokunin terraform --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.pack/skills/terraform .opencode/skills/terraform && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/terraform into .opencode/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
terraformDesign and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…
Terraform is an agent skill from EliasOulkadi/shokunin. Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD plan/apply separation. Use when user asks to write Terraform config, set up remote state, design modules, manage state, or automate infrastructure. Do NOT use for Kubernetes (use kubernetes), Docker (use docker), or CI/CD pipeline design (use ci-cd).
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `references/migration-patterns.md`, `references/stacks.md` and `scripts/plan-env.sh`). Compatibility notes: opencode
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform, Amazon DynamoDB, Docker and Kubernetes. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
terraformFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
opencode
From compatibility in the SKILL.md frontmatter.
Terraform loads about 3.4k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 919 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
GetItem` + `dynamodb:PutItem`. Check `~/.aws/credentials`. Restore bucket from backup if deleted. |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 919 words, ~3,415 tokens.
.claude/skills/terraform/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Design infrastructure as code with Terraform 1.10+ features: Stacks, test framework, provider-defined functions, and state management.
| Scale | Structure | State Strategy |
|---|---|---|
| Personal | Single main.tf | Remote backend, optional workspaces |
| Team (2-5) | envs/{dev,prod}/modules/ | Directory-per-environment, separate backends |
| Platform team | infra/{networking,compute,data,iam}/ per repo | Per-component state, terraform_remote_state |
# backend.tf
terraform {
backend "s3" {
bucket = "tf-state-{account}-{region}"
key = "{env}/{component}/terraform.tfstate"
region = "us-east-1"
encrypt = true
dynamodb_table = "tf-state-lock"
}
required_version = ">= 1.10"
required_providers {
aws = { source = "hashicorp/aws", version = "~> 5.0" }
}
}Single responsibility: one module = one domain.
modules/
├ networking/
│ main.tf, variables.tf, outputs.tf
├ compute/
│ main.tf, variables.tf, outputs.tf
└ database/
main.tf, variables.tf, outputs.tf
environments/
├ prod/
│ backend.tf -> key = "prod/compute/terraform.tfstate"
│ main.tf module "compute" { source = "../../modules/compute" }
│ terraform.tfvars
└ dev/resource "aws_db_instance" "main" {
allocated_storage = 100
engine = "postgres"
engine_version = "16.3"
instance_class = "db.r6g.large"
lifecycle {
postcondition {
condition = self.engine == "postgres"
error_message = "Only PostgreSQL is supported"
}
}
}
data "aws_iam_policy_document" "example" {
statement {
actions = ["s3:GetObject"]
condition {
test = "Bool"
variable = "aws:SecureTransport"
values = ["true"]
}
condition {
test = "IpAddress"
variable = "aws:SourceIp"
values = var.allowed_ips
}
}
lifecycle {
precondition {
condition = length(var.allowed_ips) > 0
error_message = "At least one allowed IP must be specified"
}
}
}# Instead of manual state mv, code-review it:
moved {
from = aws_s3_bucket.old
to = module.storage.aws_s3_bucket.main
}
# To remove a resource from state without destroying it:
removed {
from = aws_instance.legacy
lifecycle {
destroy = false # Keep the resource alive
}
}Stacks enable deployment of multiple configurations with shared state:
# stacks/stack.hcl
stack "dev" {
source = "./infrastructure"
path = "dev"
}
stack "prod" {
source = "./infrastructure"
path = "prod"
}# Built-in providers now expose functions
result = provider::aws::arn_parse("arn:aws:s3:::my-bucket")
# or
result = provider::aws::arn_build("s3", "my-bucket", "", "us-east-1")# tests/example.tftest.hcl
run "create_bucket" {
command = apply
variables {
bucket_name = "test-bucket-${run_id}"
}
assert {
condition = aws_s3_bucket.main.bucket == "test-bucket-${run_id}"
error_message = "Bucket name mismatch"
}
}
run "verify_encryption" {
command = apply
assert {
condition = aws_s3_bucket.main.server_side_encryption_configuration[0].rule[0].apply_server_side_encryption_by_default[0].sse_algorithm == "AES256"
error_message = "Bucket must have AES256 encryption"
}
}terraform test| Rule | Why |
|---|---|
| Remote state always | Local is single-player |
| S3 + DynamoDB | Standard state storage + locking |
| Versioning on state bucket | Rollback bad apply |
| KMS encryption | State files contain secrets |
| Per-environment isolation | destroy in dev should never touch prod |
| Per-component state | Change IAM should not re-evaluate RDS |
| Directory-per-environment preferred | Workspaces share backend — too easy to select prod by accident |
moved blocks over state rm/mv | Code-reviewed, reversible, self-documenting |
export TF_PLUGIN_CACHE_DIR="$HOME/.terraform.d/plugin-cache"
# Share cache across projects
mkdir -p $TF_PLUGIN_CACHE_DIRname: Terraform
on: [pull_request, push]
jobs:
plan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: hashicorp/setup-terraform@v3
- run: terraform init
- run: terraform fmt -check
- run: terraform validate
- run: terraform plan -out=tfplan
- uses: actions/upload-artifact@v4
with: { name: tfplan, path: tfplan }
apply:
if: github.ref == 'refs/heads/main'
needs: [plan]
runs-on: ubuntu-latest
environment: production
steps:
- uses: actions/checkout@v4
- uses: hashicorp/setup-terraform@v3
- run: terraform init
- uses: actions/download-artifact@v4
with: { name: tfplan }
- run: terraform apply tfplan| Situation | Command |
|---|---|
| Remove resource from state | terraform state rm <address> |
| Import existing resource | terraform import <address> <id> |
| Move resource (refactoring) | terraform state mv <from> <to> |
| Unlock stuck state | terraform force-unlock <lock-id> |
| Rollback corrupted state | Restore previous S3 version |
| List resources | terraform state list |
| Show resource details | terraform state show <address> |
concurrency prevents simultaneous appliesterraform validate + fmt -check in CIlatest)sensitive = true on outputs| Anti-pattern | Fix |
|---|---|
| Local state in team project | Remote state (S3 + DynamoDB) |
| One giant state file | Split by component |
| Workspaces for env isolation | Directory-per-environment |
Manual state mv instead of moved blocks | Code-reviewed moved blocks |
latest provider version | Pin ~> 5.0 |
Running apply from laptop | CI/CD with saved plan |
| No locking | DynamoDB table for state lock |
| Secrets in state outputs | Mark sensitive = true, use external secrets manager |
| No preconditions/postconditions | Add for security-critical resources |
When reviewing terraform plan output, verify these checks:
| Before | After | Why |
|---|---|---|
Blind terraform apply without reviewing plan | Read plan output fully. Check for forces replacement on stateful resources (DBs, disks). | Replacement destroys and recreates the resource, losing data. Flag it before applying. |
latest provider version in required_providers | Pin to ~> 5.0 or specific version | Provider updates can change resource defaults silently. Pin for reproducibility. |
Local state file (terraform.tfstate) in team project | Remote backend with S3/GCS + DynamoDB locking | Local state causes conflicts. Remote state with locking prevents simultaneous applies. |
| Workspaces for environment isolation | Separate directories per environment or Terraform Stacks | Workspaces share the same backend and code. Accidental terraform workspace select production when targeting staging is a real risk. |
| Scenario | Cause | Diagnosis | Fix |
|---|---|---|---|
| State lock timeout | Another process holds the lock (CI stuck, manual apply abandoned) | terraform force-unlock -force will show lock ID and holder | Kill the holding process first. If process is dead, terraform force-unlock <lock-id>. Set max_retries in backend config. |
| Provider version mismatch | required_providers version constraint doesn't match lock file (.terraform.lock.hcl) | terraform init fails with "provider version constraints changed" | Run terraform init -upgrade to update lock file. Pin versions with ~> not >=. Commit lock file. |
| Plan diff too large (>5000 lines) | Drift from manual console changes, or too many resources in one state file | Plan output is unreadable, review impossible | Split into smaller component state files. Use terraform plan -target for targeted review. Run terraform refresh to sync state. Consider -parallelism=1 for slow APIs. |
| Apply timeout | API throttling, resource creation taking >30min, network issues | Apply hangs or exits with timeout error | Increase -lock-timeout=30m. Check cloud provider status page. Split into smaller applies. Set resource timeouts {} blocks. Use TF_LOG=DEBUG for verbose output. |
| Backend unreachable | S3 bucket deleted, IAM role expired, network partition | terraform init or terraform plan fails with "Failed to load backend" | Verify S3 bucket exists and IAM role has s3:GetObject + s3:PutObject + dynamodb:GetItem + dynamodb:PutItem. Check ~/.aws/credentials. Restore bucket from backup if deleted. |
| Workspace inconsistency | Wrong workspace selected (default vs prod), stale plan file | Apply fails on unexpected resource diffs or destroys | Always terraform workspace show before plan/apply. Use directory-per-environment to eliminate workspace risk. Delete stale .tfplan files after apply. |
# List resources in state
terraform state list
# Show specific resource
terraform state show aws_instance.web
# Move resource between state files
terraform state mv -state-out=prod.tfstate aws_instance.web aws_instance.web
# Remove resource from state (keeps real resource)
terraform state rm aws_instance.old_server
# Import existing resource into state
terraform import aws_instance.web i-1234567890abcdef0terraform {
required_providers {
aws = { source = "hashicorp/aws"; version = "~> 5.0" }
kubernetes = { source = "hashicorp/kubernetes"; version = ">= 2.20, < 3.0" }
}
}Rules: ~> for minor updates (5.0-5.x). >= X, < Y for explicit ranges. Never latest.
# Infracost (open source)
infracost breakdown --path . --format table
# Terraform Cloud cost estimation (paid)
# Enabled automatically in Terraform Cloud workspaces
# Manual: cost per resource type
# EC2: instance_type * hours * region_price
# RDS: instance_class * hours + storage_gb * 0.115
# S3: gb_stored * 0.023 + requests * 0.0004
# Tag for cost allocation
resource "aws_instance" "web" {
tags = { CostCenter = "engineering", Environment = "production" }
}Before terraform apply:
terraform fmt -recursive passes — all files consistently formattedterraform validate passes — syntax and reference errors caughtterraform plan reviewed — no unexpected resource replacementsprevent_destroy = true in lifecycle block~> X.Y or exact version), never latestcondition = var.instance_count > 0)moved blocks for renamed resources (never terraform state mv manually)sensitive = trueterraform apply runs from CI/CD, not a developer laptop© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references, assets) in .pack/skills/terraform of EliasOulkadi/shokunin.
Open the folder on GitHubat commit 4c68e5b
Terraform next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Terraform this skillEliasOulkadi/shokunin | 114 | — | ~3.4k | Automated safety check: Warn | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Supercheck Infrastructure Deploymentsupercheck-io/supercheck | 215 | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | |
| Iac CheckovAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.6k | Automated safety check: Pass | Custom licence | |
| Devops Excellencemajiayu000/spellbook | 287 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Devops Deploymentyonatangross/orchestkit | 292 | — | ~2.7k | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
supercheck-io/supercheck
Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.
AgentSecOps/SecOpsAgentKit
Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates.
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
yonatangross/orchestkit
A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.
jwynia/agent-skills
Detect security misconfigurations in config files, Docker, and IaC.
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
EliasOulkadi/shokunin
Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…
EliasOulkadi/shokunin
PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…
EliasOulkadi/shokunin
Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…
EliasOulkadi/shokunin
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…
EliasOulkadi/shokunin
Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…
Works with
Categories
Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…. Terraform is an agent skill from EliasOulkadi/shokunin. Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD plan/apply separation.
Terraform fits situations like: user asks to write Terraform config; set up remote state; automate infrastructure; Kubernetes (use kubernetes).
Run `npx skills add EliasOulkadi/shokunin --skill terraform -a claude-code`. Or copy the skill folder (.pack/skills/terraform in EliasOulkadi/shokunin) into .claude/skills/terraform in your project. Claude Code loads it when a task matches its description.
Run `npx skills add EliasOulkadi/shokunin --skill terraform -a codex`. Or copy the skill folder (.pack/skills/terraform in EliasOulkadi/shokunin) into .agents/skills/terraform in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill terraform -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform, .gemini/skills/terraform, .github/skills/terraform and .opencode/skills/terraform in your project.
Going by SKILL.md and its folder, Terraform needs a shell for the scripts in its folder and the command-line tools its instructions call (terraform). Our summary lists: A Bash shell; Docker. Compatibility (from SKILL.md): opencode.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Terraform is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Terraform: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars), Iac Checkov (AgentSecOps/SecOpsAgentKit, 220 stars) and Devops Excellence (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.
Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.