Agent skill

Terraform

by EliasOulkadi in EliasOulkadi/shokunin

Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…

MITAuto-check: warningsDevOps & Cloud

Install Terraform

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add EliasOulkadi/shokunin --skill terraform -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EliasOulkadi/shokunin terraform --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/terraform .claude/skills/terraform && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
terraform
GitHub stars
114
Token cost
~3.4k tokens
SKILL.md length
919 words
Files
8 (incl. scripts, references, assets)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…

  • Works in 5 steps: Determine project structure → Bootstrap remote backend → Design modules → …
  • User asks to write Terraform config
  • SKILL.md covers Workflow, Terraform Stacks (2025+), Provider-defined Functions… and Testing Framework, plus 14 more sections
  • Runs Shell scripts from its folder; calls terraform

What it does

Terraform is an agent skill from EliasOulkadi/shokunin. Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD plan/apply separation. Use when user asks to write Terraform config, set up remote state, design modules, manage state, or automate infrastructure. Do NOT use for Kubernetes (use kubernetes), Docker (use docker), or CI/CD pipeline design (use ci-cd).

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `references/migration-patterns.md`, `references/stacks.md` and `scripts/plan-env.sh`). Compatibility notes: opencode

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform, Amazon DynamoDB, Docker and Kubernetes. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.

When your agent uses it

  • User asks to write Terraform config
  • Set up remote state
  • Automate infrastructure
  • Kubernetes (use kubernetes)

Example prompts

  • “/terraform”

Requirements

  • A Bash shell
  • Docker
  • Compatibility (from SKILL.md): opencode

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Determine project structure
  2. Bootstrap remote backend
  3. Design modules
  4. Use preconditions/postconditions
  5. Use moved and removed blocks for refactoring

What it can do on your machine

Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Terraform loads about 3.4k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 919 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:316
    GetItem` + `dynamodb:PutItem`. Check `~/.aws/credentials`. Restore bucket from backup if deleted. |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 919 words, ~3,415 tokens.

Download SKILL.mdSave it as .claude/skills/terraform/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
terraform
description
Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD plan/apply separation. Use when user asks to write Terraform config, set up remote state, design modules, manage state, or automate infrastructure. Do NOT use for Kubernetes (use kubernetes), Docker (use docker), or CI/CD pipeline design (use ci-cd).
compatibility
opencode
triggers
Terraform, infrastructure as code, IaC, terraform plan, terraform apply, terraform state, remote backend, provision infrastructure, cloud resources, AWS…
negatives
Kubernetes, Docker, CI/CD, Ansible, Pulumi, CloudFormation
license
MIT
metadata.workflow
infrastructure
metadata.audience
devops
metadata.version
2.0.0

Terraform Architect

Design infrastructure as code with Terraform 1.10+ features: Stacks, test framework, provider-defined functions, and state management.

Workflow

Step 1: Determine project structure
ScaleStructureState Strategy
PersonalSingle main.tfRemote backend, optional workspaces
Team (2-5)envs/{dev,prod}/modules/Directory-per-environment, separate backends
Platform teaminfra/{networking,compute,data,iam}/ per repoPer-component state, terraform_remote_state
Step 2: Bootstrap remote backend
hcl
# backend.tf
terraform {
  backend "s3" {
    bucket         = "tf-state-{account}-{region}"
    key            = "{env}/{component}/terraform.tfstate"
    region         = "us-east-1"
    encrypt        = true
    dynamodb_table = "tf-state-lock"
  }
  required_version = ">= 1.10"
  required_providers {
    aws = { source = "hashicorp/aws", version = "~> 5.0" }
  }
}
Step 3: Design modules

Single responsibility: one module = one domain.

modules/
├ networking/
│   main.tf, variables.tf, outputs.tf
├ compute/
│   main.tf, variables.tf, outputs.tf
└ database/
    main.tf, variables.tf, outputs.tf
environments/
├ prod/
│   backend.tf -> key = "prod/compute/terraform.tfstate"
│   main.tf       module "compute" { source = "../../modules/compute" }
│   terraform.tfvars
└ dev/
Step 4: Use preconditions/postconditions
hcl
resource "aws_db_instance" "main" {
  allocated_storage = 100
  engine = "postgres"
  engine_version = "16.3"
  instance_class = "db.r6g.large"

  lifecycle {
    postcondition {
      condition     = self.engine == "postgres"
      error_message = "Only PostgreSQL is supported"
    }
  }
}

data "aws_iam_policy_document" "example" {
  statement {
    actions = ["s3:GetObject"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["true"]
    }

    condition {
      test     = "IpAddress"
      variable = "aws:SourceIp"
      values   = var.allowed_ips
    }
  }

  lifecycle {
    precondition {
      condition     = length(var.allowed_ips) > 0
      error_message = "At least one allowed IP must be specified"
    }
  }
}
Step 5: Use moved and removed blocks for refactoring
hcl
# Instead of manual state mv, code-review it:
moved {
  from = aws_s3_bucket.old
  to   = module.storage.aws_s3_bucket.main
}

# To remove a resource from state without destroying it:
removed {
  from = aws_instance.legacy
  lifecycle {
    destroy = false  # Keep the resource alive
  }
}

Terraform Stacks (2025+)

Stacks enable deployment of multiple configurations with shared state:

hcl
# stacks/stack.hcl
stack "dev" {
  source = "./infrastructure"
  path   = "dev"
}

stack "prod" {
  source = "./infrastructure"
  path   = "prod"
}

Provider-defined Functions (1.10+)

hcl
# Built-in providers now expose functions
result = provider::aws::arn_parse("arn:aws:s3:::my-bucket")
# or
result = provider::aws::arn_build("s3", "my-bucket", "", "us-east-1")

Testing Framework

hcl
# tests/example.tftest.hcl
run "create_bucket" {
  command = apply
  variables {
    bucket_name = "test-bucket-${run_id}"
  }
  assert {
    condition     = aws_s3_bucket.main.bucket == "test-bucket-${run_id}"
    error_message = "Bucket name mismatch"
  }
}

run "verify_encryption" {
  command = apply
  assert {
    condition     = aws_s3_bucket.main.server_side_encryption_configuration[0].rule[0].apply_server_side_encryption_by_default[0].sse_algorithm == "AES256"
    error_message = "Bucket must have AES256 encryption"
  }
}
bash
terraform test

State Management Rules

RuleWhy
Remote state alwaysLocal is single-player
S3 + DynamoDBStandard state storage + locking
Versioning on state bucketRollback bad apply
KMS encryptionState files contain secrets
Per-environment isolationdestroy in dev should never touch prod
Per-component stateChange IAM should not re-evaluate RDS
Directory-per-environment preferredWorkspaces share backend — too easy to select prod by accident
moved blocks over state rm/mvCode-reviewed, reversible, self-documenting

Provider Caching (CI speedup)

bash
export TF_PLUGIN_CACHE_DIR="$HOME/.terraform.d/plugin-cache"

# Share cache across projects
mkdir -p $TF_PLUGIN_CACHE_DIR

CI/CD Pipeline

yaml
name: Terraform
on: [pull_request, push]
jobs:
  plan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: hashicorp/setup-terraform@v3
      - run: terraform init
      - run: terraform fmt -check
      - run: terraform validate
      - run: terraform plan -out=tfplan
      - uses: actions/upload-artifact@v4
        with: { name: tfplan, path: tfplan }

  apply:
    if: github.ref == 'refs/heads/main'
    needs: [plan]
    runs-on: ubuntu-latest
    environment: production
    steps:
      - uses: actions/checkout@v4
      - uses: hashicorp/setup-terraform@v3
      - run: terraform init
      - uses: actions/download-artifact@v4
        with: { name: tfplan }
      - run: terraform apply tfplan

Emergency State Surgery

SituationCommand
Remove resource from stateterraform state rm <address>
Import existing resourceterraform import <address> <id>
Move resource (refactoring)terraform state mv <from> <to>
Unlock stuck stateterraform force-unlock <lock-id>
Rollback corrupted stateRestore previous S3 version
List resourcesterraform state list
Show resource detailsterraform state show <address>

Production Checklist

  • Remote backend S3 + DynamoDB locking
  • KMS encryption on state bucket
  • Versioning enabled on state bucket
  • Public access blocked on state bucket
  • Per-environment state isolation
  • Per-component state files
  • State access IAM roles (least privilege)
  • Plan on PR, apply only from CI
  • concurrency prevents simultaneous applies
  • terraform validate + fmt -check in CI
  • Module versions pinned (not latest)
  • Secrets as sensitive = true on outputs
  • No secrets in state (Vault / AWS Secrets Manager)

Anti-Patterns

Anti-patternFix
Local state in team projectRemote state (S3 + DynamoDB)
One giant state fileSplit by component
Workspaces for env isolationDirectory-per-environment
Manual state mv instead of moved blocksCode-reviewed moved blocks
latest provider versionPin ~> 5.0
Running apply from laptopCI/CD with saved plan
No lockingDynamoDB table for state lock
Secrets in state outputsMark sensitive = true, use external secrets manager
No preconditions/postconditionsAdd for security-critical resources

Plan Review Format (Required)

When reviewing terraform plan output, verify these checks:

BeforeAfterWhy
Blind terraform apply without reviewing planRead plan output fully. Check for forces replacement on stateful resources (DBs, disks).Replacement destroys and recreates the resource, losing data. Flag it before applying.
latest provider version in required_providersPin to ~> 5.0 or specific versionProvider updates can change resource defaults silently. Pin for reproducibility.
Local state file (terraform.tfstate) in team projectRemote backend with S3/GCS + DynamoDB lockingLocal state causes conflicts. Remote state with locking prevents simultaneous applies.
Workspaces for environment isolationSeparate directories per environment or Terraform StacksWorkspaces share the same backend and code. Accidental terraform workspace select production when targeting staging is a real risk.
Show full SKILL.md (436 more words)Show less

Error Handling

ScenarioCauseDiagnosisFix
State lock timeoutAnother process holds the lock (CI stuck, manual apply abandoned)terraform force-unlock -force will show lock ID and holderKill the holding process first. If process is dead, terraform force-unlock <lock-id>. Set max_retries in backend config.
Provider version mismatchrequired_providers version constraint doesn't match lock file (.terraform.lock.hcl)terraform init fails with "provider version constraints changed"Run terraform init -upgrade to update lock file. Pin versions with ~> not >=. Commit lock file.
Plan diff too large (>5000 lines)Drift from manual console changes, or too many resources in one state filePlan output is unreadable, review impossibleSplit into smaller component state files. Use terraform plan -target for targeted review. Run terraform refresh to sync state. Consider -parallelism=1 for slow APIs.
Apply timeoutAPI throttling, resource creation taking >30min, network issuesApply hangs or exits with timeout errorIncrease -lock-timeout=30m. Check cloud provider status page. Split into smaller applies. Set resource timeouts {} blocks. Use TF_LOG=DEBUG for verbose output.
Backend unreachableS3 bucket deleted, IAM role expired, network partitionterraform init or terraform plan fails with "Failed to load backend"Verify S3 bucket exists and IAM role has s3:GetObject + s3:PutObject + dynamodb:GetItem + dynamodb:PutItem. Check ~/.aws/credentials. Restore bucket from backup if deleted.
Workspace inconsistencyWrong workspace selected (default vs prod), stale plan fileApply fails on unexpected resource diffs or destroysAlways terraform workspace show before plan/apply. Use directory-per-environment to eliminate workspace risk. Delete stale .tfplan files after apply.

State Surgery

bash
# List resources in state
terraform state list

# Show specific resource
terraform state show aws_instance.web

# Move resource between state files
terraform state mv -state-out=prod.tfstate aws_instance.web aws_instance.web

# Remove resource from state (keeps real resource)
terraform state rm aws_instance.old_server

# Import existing resource into state
terraform import aws_instance.web i-1234567890abcdef0

Provider Pinning Strategy

hcl
terraform {
  required_providers {
    aws = { source = "hashicorp/aws"; version = "~> 5.0" }
    kubernetes = { source = "hashicorp/kubernetes"; version = ">= 2.20, < 3.0" }
  }
}

Rules: ~> for minor updates (5.0-5.x). >= X, < Y for explicit ranges. Never latest.

Cost Estimation

bash
# Infracost (open source)
infracost breakdown --path . --format table

# Terraform Cloud cost estimation (paid)
# Enabled automatically in Terraform Cloud workspaces

# Manual: cost per resource type
# EC2: instance_type * hours * region_price
# RDS: instance_class * hours + storage_gb * 0.115
# S3: gb_stored * 0.023 + requests * 0.0004

# Tag for cost allocation
resource "aws_instance" "web" {
  tags = { CostCenter = "engineering", Environment = "production" }
}

Sources

  • Terraform Documentation (developer.hashicorp.com/terraform)
  • Terraform Stacks — HCP documentation
  • Terraform Test Framework — developer.hashicorp.com
  • HashiCorp Learn: moved blocks
  • AWS Well-Architected IaC patterns
  • Gruntwork — Terraform best practices

Pre-Apply Checklist

Before terraform apply:

  • terraform fmt -recursive passes — all files consistently formatted
  • terraform validate passes — syntax and reference errors caught
  • terraform plan reviewed — no unexpected resource replacements
  • Stateful resources (RDS, S3, disks) have prevent_destroy = true in lifecycle block
  • Remote backend configured with state locking (DynamoDB for S3, etc.)
  • Provider versions pinned (~> X.Y or exact version), never latest
  • Preconditions/postconditions on critical resources (e.g., condition = var.instance_count > 0)
  • moved blocks for renamed resources (never terraform state mv manually)
  • Sensitive outputs marked with sensitive = true
  • Plan file reviewed by a second person for production changes
  • terraform apply runs from CI/CD, not a developer laptop

Checklist

  • Skill loads without errors in the AI agent
  • YAML frontmatter is valid (description, compatibility, audience)
  • Workflow section provides clear step-by-step instructions
  • Error handling section covers common failure modes
  • All referenced files (references/, scripts/, assets/) exist
  • Skill triggers correctly for intended use cases
  • No broken links or missing resources

© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in .pack/skills/terraform of EliasOulkadi/shokunin.

  • SKILL.md
  • assets/module-template/main.tf
  • assets/module-template/outputs.tf
  • assets/module-template/variables.tf
  • references/migration-patterns.md
  • references/stacks.md
  • scripts/plan-env.sh
  • scripts/validate-all.sh

Open the folder on GitHubat commit 4c68e5b

Compare with similar skills

Terraform next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Terraform compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Terraform this skillEliasOulkadi/shokunin114—~3.4kAutomated safety check: WarnMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Supercheck Infrastructure Deploymentsupercheck-io/supercheck215—~1.4kAutomated safety check: NotesAGPL-3.0
Iac CheckovAgentSecOps/SecOpsAgentKit2201 repos~4.6kAutomated safety check: PassCustom licence
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit292—~2.7kAutomated safety check: PassMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Supercheck Infrastructure Deployment

    supercheck-io/supercheck

    Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

    215 GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Iac Checkov

    AgentSecOps/SecOpsAgentKit

    Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates.

    220 GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    292 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Config Scan

    jwynia/agent-skills

    Detect security misconfigurations in config files, Docker, and IaC.

    170 GitHub stars~2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes

More from EliasOulkadi/shokunin

All 49 skills in this repo
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 6 days ago
    Auto-check: notes
  • Component Forge

    EliasOulkadi/shokunin

    Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Admin

    EliasOulkadi/shokunin

    PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…

    114 GitHub stars~2k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check: notes
  • Docker

    EliasOulkadi/shokunin

    Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

    114 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes

Categories

Questions about Terraform

What does Terraform do?

Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD…. Terraform is an agent skill from EliasOulkadi/shokunin. Design and manage infrastructure as code with Terraform — modules, remote state (S3 + DynamoDB), Stacks (deployments), test framework, preconditions/postconditions, moved/removed blocks, and CI/CD plan/apply separation.

When should I use Terraform?

Terraform fits situations like: user asks to write Terraform config; set up remote state; automate infrastructure; Kubernetes (use kubernetes).

How do I install Terraform in Claude Code?

Run `npx skills add EliasOulkadi/shokunin --skill terraform -a claude-code`. Or copy the skill folder (.pack/skills/terraform in EliasOulkadi/shokunin) into .claude/skills/terraform in your project. Claude Code loads it when a task matches its description.

How do I install Terraform in Codex?

Run `npx skills add EliasOulkadi/shokunin --skill terraform -a codex`. Or copy the skill folder (.pack/skills/terraform in EliasOulkadi/shokunin) into .agents/skills/terraform in your project. Codex loads it when a task matches its description.

Can I use Terraform in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill terraform -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform, .gemini/skills/terraform, .github/skills/terraform and .opencode/skills/terraform in your project.

What does Terraform need to run?

Going by SKILL.md and its folder, Terraform needs a shell for the scripts in its folder and the command-line tools its instructions call (terraform). Our summary lists: A Bash shell; Docker. Compatibility (from SKILL.md): opencode.

Does Terraform access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Terraform safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Terraform use?

Terraform is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Terraform use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Terraform?

Skills that share tags, products or a category with Terraform: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars), Iac Checkov (AgentSecOps/SecOpsAgentKit, 220 stars) and Devops Excellence (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Terraform?

EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.

Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.