Agent skill

Oma Tf Infra

by first-fluke in first-fluke/oh-my-agent

Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

MITAuto-check passedDevOps & Cloud

Install Oma Tf Infra

skills CLI
$ npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-fluke/oh-my-agent oma-tf-infra --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/benchmarks/runs/oma/.agents/skills/oma-tf-infra .claude/skills/oma-tf-infra && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oma-tf-infra
GitHub stars
1.3k
Token cost
~2.8k tokens
SKILL.md length
1,200 words
Files
9
Skills in repo
57
Repo updated
First seen
Licence
MIT

At a glance

Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

  • Works in 3 steps: Detect provider and environment from… → Identify state backend, module… → Determine whether task is design,…
  • Terraform plan/apply
  • SKILL.md covers Scheduling, Structural Flow, Logical Operations and References
  • Calls terraform

What it does

Oma Tf Infra is an agent skill from first-fluke/oh-my-agent. Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud). Use for terraform plan/apply, state management, compute, databases, storage, networking, IAM, OIDC, cost optimization, policy-as-code, ISO/IEC 42001 AI controls, ISO 22301 continuity, and ISO/IEC/IEEE 42010 architecture documentation.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `resources/checklist.md`, `resources/cost-optimization.md` and `resources/error-playbook.md`).

It sits in DevOps & Cloud, covering Infrastructure as code, OAuth and OpenID Connect and Cloud architecture. It works with Terraform, Amazon Web Services, Google Cloud and Microsoft Azure. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.

When your agent uses it

  • Terraform plan/apply
  • State management
  • Cost optimization
  • ISO/IEC 42001 AI controls

Example prompts

  • “/oma-tf-infra”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Detect provider and environment from project context.
  2. Identify state backend, module boundaries, resources, and risk level.
  3. Determine whether task is design, implementation, review, plan analysis, or remediation.

What it can do on your machine

Read from SKILL.md and the folder at commit 268bb4a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oma Tf Infra loads about 2.8k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-fluke/oh-my-agent at commit 268bb4a, republished under its MIT licence (© first-fluke). 1,200 words, ~2,831 tokens.

Download SKILL.mdSave it as .claude/skills/oma-tf-infra/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
oma-tf-infra
description
Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud). Use for terraform plan/apply, state management, compute, databases, storage, networking, IAM, OIDC, cost optimization, policy-as-code, ISO/IEC 42001 AI controls, ISO 22301 continuity, and ISO/IEC/IEEE 42010 architecture documentation.

TF Infra Agent - Infrastructure-as-Code Specialist

Scheduling

Goal

Design, implement, review, and document Terraform-based infrastructure across cloud providers with secure state, least privilege, cost awareness, continuity, and policy/testing controls.

Intent signature
  • User asks for Terraform, IaC, cloud provisioning, state, IAM/OIDC, networking, storage, compute, databases, CDN, policy-as-code, cost optimization, drift, or terraform plan review.
  • User needs infrastructure controls for AI systems, continuity, or architecture documentation.
When to use
  • Provisioning infrastructure on any cloud provider (AWS, GCP, Azure, OCI)
  • Creating or modifying Terraform configurations for compute, databases, storage, networking
  • Configuring CI/CD authentication (OIDC, workload identity, IAM roles)
  • Setting up CDN, load balancers, object storage, message queues
  • Reviewing terraform plan output before apply
  • Troubleshooting Terraform state or resource issues
  • Migrating from manual console changes to Terraform
  • Implementing infrastructure controls for AI systems (ISO/IEC 42001)
  • Designing continuity-oriented infrastructure (ISO 22301)
  • Producing architecture documentation (ISO/IEC/IEEE 42010)
When NOT to use
  • Database schema design or query tuning -> use DB Agent
  • Backend API implementation -> use Backend Agent
  • CI/CD pipeline code (non-infrastructure) -> use Dev Workflow
  • Security/compliance audit -> use QA Agent
Expected inputs
  • Cloud provider, environment, Terraform scope, desired resources, and state/backend context
  • Existing .tf, .tfvars, modules, provider versions, CI/CD auth, plan output, or drift symptoms
  • Security, cost, continuity, policy, tagging, and documentation constraints
Expected outputs
  • Terraform code, module changes, review findings, plan analysis, or architecture/control documentation
  • Validation, formatting, plan, and policy/security scan results when applicable
  • Explicit risks around state, secrets, drift, destructive changes, and cost
Dependencies
  • Terraform CLI, provider CLIs/config, remote state backend, and policy/security scanners
  • resources/multi-cloud-examples.md, cost guide, policy/testing examples, ISO infra guide, and checklist
Control-flow features
  • Branches by provider, environment, state backend, destructive risk, policy scan result, and plan/apply intent
  • Reads and writes Terraform files; may run local Terraform/process commands
  • Must not apply/destroy production infrastructure without explicit confirmation and backup awareness

Structural Flow

Entry
  1. Detect provider and environment from project context.
  2. Identify state backend, module boundaries, resources, and risk level.
  3. Determine whether task is design, implementation, review, plan analysis, or remediation.
Scenes
  1. PREPARE: Load Terraform scope, provider, environment, and constraints.
  2. ACQUIRE: Read HCL, modules, state/backend config, CI/CD auth, and plan output.
  3. REASON: Design resources, IAM, networking, state, cost, and continuity tradeoffs.
  4. ACT: Write or review HCL, modules, variables, outputs, and docs.
  5. VERIFY: Run fmt, validate, plan, scans, and policy checks when available.
  6. FINALIZE: Report diff, plan risk, validation status, and next apply steps.
Transitions
  • If provider is unclear, detect from HCL before writing.
  • If state is local or unprotected, prioritize remote state guidance.
  • If plan includes destructive changes, stop for explicit review.
  • If production apply/destroy is requested, require confirmation and backup/rollback notes.
Failure and recovery
  • If credentials are unavailable, produce static review or code changes only.
  • If plan cannot run, report the missing provider/backend/credential blocker.
  • If policy/security scan fails, fix or report concrete remediation.
Exit
  • Success: Terraform change or review is validated and risk-scoped.
  • Partial success: unavailable credentials/tools or unreviewed apply risk is explicit.

Logical Operations

Actions
ActionSSL primitiveEvidence
Detect provider and scopeREADHCL, providers, modules
Select cloud/resource mappingSELECTMulti-cloud mapping
Write TerraformWRITE.tf, .tfvars, modules
Validate HCLCALL_TOOLterraform fmt, validate, plan
Compare plan riskCOMPAREPlan output and drift
Infer cost/security/continuity risksINFERPolicy, ISO, cost guides
Report resultNOTIFYFinal infra summary
Tools and instruments
  • Terraform CLI and provider ecosystem
  • Checkov, tfsec, OPA/Sentinel, Terratest when applicable
  • Cost, policy, multi-cloud, and ISO resource guides
Canonical command path
bash
terraform fmt -recursive
terraform validate
terraform plan -out=tfplan

Run scanners when available before any apply:

bash
checkov -d .
tfsec .
Resource scope
ScopeResource target
CODEBASETerraform modules, variables, outputs, CI config
LOCAL_FSPlans, state config, documentation
PROCESSTerraform, scanner, and policy commands
CREDENTIALSCloud provider auth and state backend credentials
NETWORKCloud APIs and remote state backends
Preconditions
  • Terraform scope and provider can be determined.
  • Required credentials are present for live plan/apply, or static mode is acceptable.
Effects and side effects
  • Mutates infrastructure code and documentation.
  • May produce plans that imply cloud resource creation, mutation, or destruction.
  • Should not directly apply/destroy without explicit user authorization.
Show full SKILL.md (541 more words)Show less
Guardrails
  1. Provider-Agnostic: Always detect cloud provider from project context before writing any HCL
  2. Remote State: Store Terraform state in remote backend (S3, GCS, Azure Blob) with versioning and locking
  3. OIDC First: Use OIDC/IAM roles for CI/CD authentication instead of long-lived credentials
  4. Plan Before Apply: Always run terraform validate, terraform fmt, terraform plan before apply
  5. Least Privilege: IAM policies must follow least privilege; never use overly permissive policies
  6. Tag Everything: Apply Environment, Project, Owner, CostCenter tags/labels to all taggable resources
  7. No Secrets in Code: Never hardcode passwords, API keys, or tokens in .tf files; use provider secret management
  8. Composable Modules: Design reusable modules with clear interfaces; avoid monolithic modules
  9. Environment Sizing: Use environment-based sizing (smaller for dev/staging, production-grade for prod)
  10. Policy as Code: Run OPA/Sentinel and security scanning (Checkov, tfsec) in CI/CD before apply
  11. Version Pinning: Version pin all providers and modules; use for_each over count (never count with computed values)
  12. Cost Awareness: Implement lifecycle policies, autoscaling schedules, and review cost estimates before apply
  13. No Auto-Approve: Never use auto-approve in production; never terraform destroy without backup/confirmation
  14. Drift Detection: Never skip drift detection in production; address deprecation warnings from providers
  15. AI Systems: Document IAM, logging, encryption, monitoring, and retention controls; prefer private connectivity; limit to infrastructure controls (note when policy/process work belongs elsewhere)
  16. Continuity: Document backup, failover, dependency visibility, and restore validation with target RTO/RPO (not backup-only)
  17. Architecture Documentation: Capture stakeholders, concerns, views, interfaces, constraints, and decisions (not a compliance checkbox; improve communication and traceability)
Cloud Provider Detection
IndicatorProvider
provider "google" or google_* resourcesGCP
provider "aws" or aws_* resourcesAWS
provider "azurerm" or azurerm_* resourcesAzure
provider "oci" or oci_* resourcesOracle Cloud
Multi-Cloud Resource Mapping
ConceptAWSGCPAzureOracle (OCI)
Container PlatformECS FargateCloud RunContainer AppsContainer Instances
Managed KubernetesEKSGKEAKSOKE
Managed DatabaseRDSCloud SQLAzure SQLAutonomous DB
Cache/In-MemoryElastiCacheMemorystoreAzure CacheOCI Cache
Object StorageS3GCSBlob StorageObject Storage
Queue/MessagingSQS/SNSPub/SubService BusOCI Streaming
Task QueueN/ACloud TasksQueue StorageN/A
CDNCloudFrontCloud CDNFront DoorOCI CDN
Load BalancerALB/NLBCloud Load BalancingLoad BalancerOCI Load Balancer
IAM RoleIAM RoleService AccountManaged IdentityDynamic Group
SecretsSecrets ManagerSecret ManagerKey VaultOCI Vault
VPCVPCVPCVirtual NetworkVCN
Serverless FunctionLambdaCloud FunctionsFunctionsOCI Functions

References

Follow resources/execution-protocol.md step by step. See resources/examples.md for input/output examples. Use resources/multi-cloud-examples.md for provider-specific HCL patterns. Use resources/cost-optimization.md for cost reduction strategies. Use resources/policy-testing-examples.md for OPA, Sentinel, and Terratest patterns. Use resources/iso-42001-infra.md for AI governance, continuity, and architecture controls. Before submitting, run resources/checklist.md. Vendor-specific execution protocols are injected automatically by oma agent:spawn. Source files live under ../_shared/runtime/execution-protocols/{vendor}.md.

  • Execution steps: resources/execution-protocol.md
  • Self-check: resources/checklist.md
  • Examples: resources/examples.md
  • Multi-cloud HCL patterns: resources/multi-cloud-examples.md
  • Cost optimization: resources/cost-optimization.md
  • Policy & testing: resources/policy-testing-examples.md
  • ISO controls: resources/iso-42001-infra.md
  • Error recovery: resources/error-playbook.md
  • Context loading: ../_shared/core/context-loading.md
  • Reasoning templates: ../_shared/core/reasoning-templates.md
  • Clarification: ../_shared/core/clarification-protocol.md
  • Context budget: ../_shared/core/context-budget.md
  • Difficulty assessment: ../_shared/core/difficulty-guide.md
  • Lessons learned: ../_shared/core/lessons-learned.md
Knowledge Reference

terraform, infrastructure-as-code, iac, cloud, aws, gcp, azure, oracle, oci, multi-cloud, devops, provisioning, infrastructure, compute, database, storage, networking, iam, oidc, workload identity, container, kubernetes, serverless, vpc, subnet, load balancer, cdn, secrets management, state management, backend, provider

© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in benchmarks/runs/oma/.agents/skills/oma-tf-infra of first-fluke/oh-my-agent.

  • SKILL.md
  • resources/checklist.md
  • resources/cost-optimization.md
  • resources/error-playbook.md
  • resources/examples.md
  • resources/execution-protocol.md
  • resources/iso-42001-infra.md
  • resources/multi-cloud-examples.md
  • resources/policy-testing-examples.md

Open the folder on GitHubat commit 268bb4a

Compare with similar skills

Oma Tf Infra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oma Tf Infra compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oma Tf Infra this skillfirst-fluke/oh-my-agent1.3k—~2.8kAutomated safety check: PassMIT
Terraform Module Librarywshobson/agents40k11 repos~1.3kAutomated safety check: PassMIT
Atmos Migrationcloudposse/atmos1.4k—~5.1kAutomated safety check: WarnApache-2.0
Cloud Architectdavila7/claude-code-templates33k8 repos~1.9kAutomated safety check: PassMIT
Terraform EngineerJeffallan/claude-skills12k—~1.4kAutomated safety check: PassMIT
Heroku To AWSaws/agent-toolkit-for-aws2.8k—~7.2kAutomated safety check: PassApache-2.0

Similar skills

  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 11 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Cloud Architect

    davila7/claude-code-templates

    Expert cloud architect specializing in AWS/Azure/GCP multi-cloud infrastructure design, advanced IaC (Terraform/OpenTofu/CDK), FinOps cost optimization, and modern architectural patterns.

    33k GitHub starsUsed in 8 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Terraform Engineer

    Jeffallan/claude-skills

    Writes reusable Terraform modules and manages state, providers and environments across AWS, Azure and GCP, with validation, plan review and explicit apply approval.

    12k GitHub stars~1.4k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Heroku To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Heroku to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~7.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Microsoft Azure to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~5.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from first-fluke/oh-my-agent

All 57 skills in this repo
  • OMA Multi-Agent Orchestration

    first-fluke/oh-my-agent

    Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.

    1.3k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • OMA Multi-Agent Orchestrator

    first-fluke/oh-my-agent

    Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.

    1.3k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Architecture Decisions and ADRs

    first-fluke/oh-my-agent

    Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.

    1.3k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • OMA Brainstorm

    first-fluke/oh-my-agent

    Explores goals, constraints and alternative designs one question at a time and saves an approved design document before any planning or coding starts.

    1.3k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Oma Coordination

    first-fluke/oh-my-agent

    Coordinate assigned specialist tasks and handoffs manually. An agent skill from first-fluke/oh-my-agent.

    1.3k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Oma Image

    first-fluke/oh-my-agent

    Generate raster images or reference-guided variations through the OMA image CLI.

    1.3k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Oma Tf Infra

What does Oma Tf Infra do?

Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud). Oma Tf Infra is an agent skill from first-fluke/oh-my-agent. Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

When should I use Oma Tf Infra?

Oma Tf Infra fits situations like: terraform plan/apply; state management; cost optimization; ISO/IEC 42001 AI controls.

How do I install Oma Tf Infra in Claude Code?

Run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a claude-code`. Or copy the skill folder (benchmarks/runs/oma/.agents/skills/oma-tf-infra in first-fluke/oh-my-agent) into .claude/skills/oma-tf-infra in your project. Claude Code loads it when a task matches its description.

How do I install Oma Tf Infra in Codex?

Run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a codex`. Or copy the skill folder (benchmarks/runs/oma/.agents/skills/oma-tf-infra in first-fluke/oh-my-agent) into .agents/skills/oma-tf-infra in your project. Codex loads it when a task matches its description.

Can I use Oma Tf Infra in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-tf-infra, .gemini/skills/oma-tf-infra, .github/skills/oma-tf-infra and .opencode/skills/oma-tf-infra in your project.

What does Oma Tf Infra need to run?

Going by SKILL.md and its folder, Oma Tf Infra needs the command-line tools its instructions call (terraform).

Does Oma Tf Infra access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oma Tf Infra safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oma Tf Infra use?

Oma Tf Infra is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oma Tf Infra use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oma Tf Infra?

Skills that share tags, products or a category with Oma Tf Infra: Terraform Module Library (wshobson/agents, 40k stars), Atmos Migration (cloudposse/atmos, 1.4k stars), Cloud Architect (davila7/claude-code-templates, 33k stars) and Terraform Engineer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oma Tf Infra?

first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,336 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 10, 2026.

Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.