Agent skill

Oma Tf Infra

by first-fluke in first-fluke/oh-my-agent

Create or review Terraform infrastructure and plans. An agent skill from first-fluke/oh-my-agent.

MITAuto-check passedDevOps & Cloud

Install Oma Tf Infra

skills CLI
$ npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-fluke/oh-my-agent oma-tf-infra --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oma-tf-infra .claude/skills/oma-tf-infra && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oma-tf-infra
GitHub stars
1.3k
Token cost
~2.8k tokens
SKILL.md length
1,229 words
Files
30 (incl. references)
Skills in repo
57
Repo updated
First seen
Licence
MIT

At a glance

Create or review Terraform infrastructure and plans. An agent skill from first-fluke/oh-my-agent.

  • Works in 3 steps: Detect provider and environment from… → Identify state backend, module… → Determine whether task is design,…
  • Cloud resources
  • SKILL.md covers Scheduling, Structural Flow, Logical Operations and References
  • Calls terraform and trivy

What it does

Oma Tf Infra is an agent skill from first-fluke/oh-my-agent. Create or review Terraform infrastructure and plans. Use for cloud resources, IAM, networking, state management, and infrastructure changes.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 34 other files, including reference files (for example `references/_shared/conditional/experiment-ledger.md`, `references/_shared/conditional/exploration-loop.md` and `references/_shared/conditional/quality-score.md`).

It sits in DevOps & Cloud, covering Infrastructure as code and State management. It works with Terraform. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.

When your agent uses it

  • Cloud resources
  • State management
  • Infrastructure changes

Example prompts

  • “/oma-tf-infra”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Detect provider and environment from project context.
  2. Identify state backend, module boundaries, resources, and risk level.
  3. Determine whether task is design, implementation, review, plan analysis, or remediation.

What it can do on your machine

Read from SKILL.md and the folder at commit 268bb4a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oma Tf Infra loads about 2.8k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 38 tokens; SKILL.md has 1,229 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-fluke/oh-my-agent at commit 268bb4a, republished under its MIT licence (© first-fluke). 1,229 words, ~2,832 tokens.

Download SKILL.mdSave it as .claude/skills/oma-tf-infra/SKILL.md (or your agent's skills folder). This skill also uses 29 other files; get the full folder from GitHub.
name
oma-tf-infra
description
Create or review Terraform infrastructure and plans. Use for cloud resources, IAM, networking, state management, and infrastructure changes.

TF Infra Agent - Infrastructure-as-Code Specialist

Scheduling

Goal

Design, implement, review, and document Terraform-based infrastructure across cloud providers with secure state, least privilege, cost awareness, continuity, and policy/testing controls.

Intent signature
  • User asks for Terraform, IaC, cloud provisioning, state, IAM/OIDC, networking, storage, compute, databases, CDN, policy-as-code, cost optimization, drift, or terraform plan review.
  • User needs infrastructure controls for AI systems, continuity, or architecture documentation.
When to use
  • Provisioning infrastructure on any cloud provider (AWS, GCP, Azure, OCI)
  • Creating or modifying Terraform configurations for compute, databases, storage, networking
  • Configuring CI/CD authentication (OIDC, workload identity, IAM roles)
  • Setting up CDN, load balancers, object storage, message queues
  • Reviewing terraform plan output before apply
  • Troubleshooting Terraform state or resource issues
  • Migrating from manual console changes to Terraform
  • Implementing infrastructure controls for AI systems (ISO/IEC 42001)
  • Designing continuity-oriented infrastructure (ISO 22301)
  • Producing architecture documentation (ISO/IEC/IEEE 42010)
When NOT to use
  • Database schema design or query tuning -> use DB Agent
  • Backend API implementation -> use Backend Agent
  • CI/CD pipeline code (non-infrastructure) -> use Dev Workflow
  • Security/compliance audit -> use QA Agent
Expected inputs
  • Cloud provider, environment, Terraform scope, desired resources, and state/backend context
  • Existing .tf, .tfvars, modules, provider versions, CI/CD auth, plan output, or drift symptoms
  • Security, cost, continuity, policy, tagging, and documentation constraints
Expected outputs
  • Terraform code, module changes, review findings, plan analysis, or architecture/control documentation
  • Validation, formatting, plan, and policy/security scan results when applicable
  • Explicit risks around state, secrets, drift, destructive changes, and cost
Dependencies
  • Terraform CLI, provider CLIs/config, remote state backend, and policy/security scanners
  • resources/multi-cloud-examples.md, cost guide, policy/testing examples, ISO infra guide, and checklist
Control-flow features
  • Branches by provider, environment, state backend, destructive risk, policy scan result, and plan/apply intent
  • Reads and writes Terraform files; may run local Terraform/process commands
  • Must not apply/destroy production infrastructure without explicit confirmation and backup awareness

Structural Flow

Entry
  1. Detect provider and environment from project context.
  2. Identify state backend, module boundaries, resources, and risk level.
  3. Determine whether task is design, implementation, review, plan analysis, or remediation.
Scenes
  1. PREPARE: Load Terraform scope, provider, environment, and constraints.
  2. ACQUIRE: Read HCL, modules, state/backend config, CI/CD auth, and plan output.
  3. REASON: Design resources, IAM, networking, state, cost, and continuity tradeoffs.
  4. ACT: Write or review HCL, modules, variables, outputs, and docs.
  5. VERIFY: Run fmt, validate, plan, scans, and policy checks when available.
  6. FINALIZE: Report diff, plan risk, validation status, and next apply steps.
Transitions
  • If provider is unclear, detect from HCL before writing.
  • If state is local or unprotected, prioritize remote state guidance.
  • If plan includes destructive changes, stop for explicit review.
  • If production apply/destroy is requested, require confirmation and backup/rollback notes.
Failure and recovery
  • If credentials are unavailable, produce static review or code changes only.
  • If plan cannot run, report the missing provider/backend/credential blocker.
  • If policy/security scan fails, fix or report concrete remediation.
Exit
  • Success: Terraform change or review is validated and risk-scoped.
  • Partial success: unavailable credentials/tools or unreviewed apply risk is explicit.

Logical Operations

Actions
ActionSSL primitiveEvidence
Detect provider and scopeREADHCL, providers, modules
Select cloud/resource mappingSELECTMulti-cloud mapping
Write TerraformWRITE.tf, .tfvars, modules
Validate HCLCALL_TOOLterraform fmt, validate, plan
Compare plan riskCOMPAREPlan output and drift
Infer cost/security/continuity risksINFERPolicy, ISO, cost guides
Report resultNOTIFYFinal infra summary
Tools and instruments
  • Terraform CLI (or OpenTofu as a drop-in) and provider ecosystem
  • Checkov, Trivy (trivy config, successor to tfsec), OPA/Sentinel, native terraform test, Terratest when applicable
  • Infracost for plan-time cost estimation when available
  • Cost, policy, multi-cloud, and ISO resource guides
Canonical command path
bash
terraform init            # required before validate/plan (-backend=false for static-only checks)
terraform fmt -recursive
terraform validate
terraform plan -out=tfplan

Run scanners when available before any apply:

bash
checkov -d .
trivy config .   # tfsec is in maintenance mode; Trivy is its successor
Resource scope
ScopeResource target
CODEBASETerraform modules, variables, outputs, CI config
LOCAL_FSPlans, state config, documentation
PROCESSTerraform, scanner, and policy commands
CREDENTIALSCloud provider auth and state backend credentials
NETWORKCloud APIs and remote state backends
Preconditions
  • Terraform scope and provider can be determined.
  • Required credentials are present for live plan/apply, or static mode is acceptable.
Effects and side effects
  • Mutates infrastructure code and documentation.
  • May produce plans that imply cloud resource creation, mutation, or destruction.
  • Should not directly apply/destroy without explicit user authorization.
Show full SKILL.md (550 more words)Show less
Guardrails
  1. Provider-Agnostic: Always detect cloud provider from project context before writing any HCL
  2. Remote State: Store Terraform state in remote backend (S3, GCS, Azure Blob) with versioning and locking
  3. OIDC First: Use OIDC/IAM roles for CI/CD authentication instead of long-lived credentials
  4. Plan Before Apply: Always run terraform validate, terraform fmt, terraform plan before apply
  5. Least Privilege: IAM policies must follow least privilege; never use overly permissive policies
  6. Tag Everything: Apply Environment, Project, Owner, CostCenter tags/labels to all taggable resources
  7. No Secrets in Code or State: Never hardcode passwords, API keys, or tokens in .tf files; use provider secret management. Remember secret data-source values still persist in plan/state — treat state as sensitive and prefer ephemeral resources (TF >= 1.10) / write-only arguments (TF >= 1.11) where provider support exists
  8. Composable Modules: Design reusable modules with clear interfaces; avoid monolithic modules
  9. Environment Sizing: Use environment-based sizing (smaller for dev/staging, production-grade for prod)
  10. Policy as Code: Run OPA/Sentinel and security scanning (Checkov, Trivy) in CI/CD before apply
  11. Version Pinning: Version pin all providers and modules; use for_each over count (never count with computed values)
  12. Cost Awareness: Implement lifecycle policies, autoscaling schedules, and review cost estimates before apply
  13. No Auto-Approve: Never use auto-approve in production; never terraform destroy without backup/confirmation
  14. Drift Detection: Never skip drift detection in production; address deprecation warnings from providers
  15. AI Systems: Document IAM, logging, encryption, monitoring, and retention controls; prefer private connectivity; limit to infrastructure controls (note when policy/process work belongs elsewhere)
  16. Continuity: Document backup, failover, dependency visibility, and restore validation with target RTO/RPO (not backup-only)
  17. Architecture Documentation: Capture stakeholders, concerns, views, interfaces, constraints, and decisions (not a compliance checkbox; improve communication and traceability)
Cloud Provider Detection
IndicatorProvider
provider "google" or google_* resourcesGCP
provider "aws" or aws_* resourcesAWS
provider "azurerm" or azurerm_* resourcesAzure
provider "oci" or oci_* resourcesOracle Cloud
Multi-Cloud Resource Mapping
ConceptAWSGCPAzureOracle (OCI)
Container PlatformECS FargateCloud RunContainer AppsContainer Instances
Managed KubernetesEKSGKEAKSOKE
Managed DatabaseRDSCloud SQLAzure SQLAutonomous DB
Cache/In-MemoryElastiCacheMemorystoreAzure CacheOCI Cache
Object StorageS3GCSBlob StorageObject Storage
Queue/MessagingSQS/SNSPub/SubService BusOCI Streaming
Task QueueN/ACloud TasksQueue StorageN/A
CDNCloudFrontCloud CDNFront DoorOCI CDN
Load BalancerALB/NLBCloud Load BalancingLoad BalancerOCI Load Balancer
IAM RoleIAM RoleService AccountManaged IdentityDynamic Group
SecretsSecrets ManagerSecret ManagerKey VaultOCI Vault
VPCVPCVPCVirtual NetworkVCN
Serverless FunctionLambdaCloud FunctionsFunctionsOCI Functions

References

  • Execution steps (follow for the selected task): resources/execution-protocol.md
  • Self-check (run before handoff): resources/checklist.md
  • Examples: resources/examples.md
  • Multi-cloud HCL patterns: resources/multi-cloud-examples.md
  • Cost optimization: resources/cost-optimization.md
  • Policy & testing: resources/policy-testing-examples.md
  • ISO controls: resources/iso-42001-infra.md
  • Error recovery: resources/error-playbook.md
  • Context loading: references/_shared/core/context-loading.md
  • Clarification: references/_shared/core/clarification-protocol.md
  • Context budget: references/_shared/core/context-budget.md
  • Task decomposition: references/_shared/core/difficulty-guide.md (unresolved scope or dependencies)
  • Lessons learned: references/_shared/core/lessons-learned.md (matching prior failure or requested retrospective)
  • Observability handoff: ../oma-observability/SKILL.md §Integrations — Collector topology, transport tuning, release metadata
Knowledge Reference

terraform, opentofu, infrastructure-as-code, iac, cloud, aws, gcp, azure, oracle, oci, multi-cloud, devops, provisioning, infrastructure, compute, database, storage, networking, iam, oidc, workload identity, container, kubernetes, serverless, vpc, subnet, load balancer, cdn, secrets management, ephemeral resources, write-only arguments, state management, drift, import block, terraform test, trivy, checkov, infracost, backend, provider

© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 29 other files (references) in skills/oma-tf-infra of first-fluke/oh-my-agent.

  • SKILL.md
  • references/_shared/conditional/experiment-ledger.md
  • references/_shared/conditional/exploration-loop.md
  • references/_shared/conditional/quality-score.md
  • references/_shared/core/api-contracts/README.md
  • references/_shared/core/api-contracts/template.md
  • references/_shared/core/clarification-protocol.md
  • references/_shared/core/common-checklist.md
  • references/_shared/core/context-budget.md
  • references/_shared/core/context-loading.md
  • references/_shared/core/difficulty-guide.md
  • references/_shared/core/execution-policy.md
  • references/_shared/core/lessons-learned.md
  • references/_shared/core/prompt-structure.md
  • references/_shared/core/session-metrics.md
  • references/_shared/core/skill-routing.md
  • … and 14 more

Open the folder on GitHubat commit 268bb4a

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in first-fluke/oh-my-agent, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Oma Tf Infra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oma Tf Infra compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oma Tf Infra this skillfirst-fluke/oh-my-agent1.3k—~2.8kAutomated safety check: PassMIT
Terraform Specialistdavila7/claude-code-templates33k8 repos~2.3kAutomated safety check: PassMIT
Sdaf State ManagementAzure/sap-automation146—~1.7kAutomated safety check: PassMIT
TerraformRightNow-AI/openfang18k—~645Automated safety check: PassApache-2.0
Terraform Provider Upgradethomast1906/github-copilot-agent-skills202—~3.9kAutomated safety check: PassNone
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Terraform Specialist

    davila7/claude-code-templates

    Expert Terraform/OpenTofu specialist mastering advanced IaC automation, state management, and enterprise infrastructure patterns.

    33k GitHub starsUsed in 8 repos~2.3k tokens
    DevOps & CloudAuto-check passed
  • Sdaf State Management

    Azure/sap-automation

    Official

    Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

    146 GitHub stars~1.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Terraform

    RightNow-AI/openfang

    Terraform IaC expert for providers, modules, state management, and planning

    18k GitHub stars~645 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Terraform Provider Upgrade

    thomast1906/github-copilot-agent-skills

    Safe Terraform provider upgrades with automatic resource migration, breaking change detection, and state management using moved blocks.

    202 GitHub stars~3.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Terraform Skill

    antonbabenko/terraform-skill

    A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…

    2.4k GitHub starsUsed in 1 repo~5.1k tokens
    DevOps & CloudAuto-check passed

More from first-fluke/oh-my-agent

All 57 skills in this repo
  • OMA Multi-Agent Orchestration

    first-fluke/oh-my-agent

    Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.

    1.3k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • OMA Multi-Agent Orchestrator

    first-fluke/oh-my-agent

    Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.

    1.3k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Architecture Decisions and ADRs

    first-fluke/oh-my-agent

    Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.

    1.3k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • OMA Brainstorm

    first-fluke/oh-my-agent

    Explores goals, constraints and alternative designs one question at a time and saves an approved design document before any planning or coding starts.

    1.3k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Oma Coordination

    first-fluke/oh-my-agent

    Coordinate assigned specialist tasks and handoffs manually. An agent skill from first-fluke/oh-my-agent.

    1.3k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Oma Image

    first-fluke/oh-my-agent

    Generate raster images or reference-guided variations through the OMA image CLI.

    1.3k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Oma Tf Infra

What does Oma Tf Infra do?

Create or review Terraform infrastructure and plans. An agent skill from first-fluke/oh-my-agent. Oma Tf Infra is an agent skill from first-fluke/oh-my-agent. Create or review Terraform infrastructure and plans.

When should I use Oma Tf Infra?

Oma Tf Infra fits situations like: cloud resources; state management; infrastructure changes.

How do I install Oma Tf Infra in Claude Code?

Run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a claude-code`. Or copy the skill folder (skills/oma-tf-infra in first-fluke/oh-my-agent) into .claude/skills/oma-tf-infra in your project. Claude Code loads it when a task matches its description.

How do I install Oma Tf Infra in Codex?

Run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a codex`. Or copy the skill folder (skills/oma-tf-infra in first-fluke/oh-my-agent) into .agents/skills/oma-tf-infra in your project. Codex loads it when a task matches its description.

Can I use Oma Tf Infra in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-tf-infra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-tf-infra, .gemini/skills/oma-tf-infra, .github/skills/oma-tf-infra and .opencode/skills/oma-tf-infra in your project.

What does Oma Tf Infra need to run?

Going by SKILL.md and its folder, Oma Tf Infra needs the command-line tools its instructions call (terraform and trivy).

Does Oma Tf Infra access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oma Tf Infra safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oma Tf Infra use?

Oma Tf Infra is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oma Tf Infra use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Oma Tf Infra?

Skills that share tags, products or a category with Oma Tf Infra: Terraform Specialist (davila7/claude-code-templates, 33k stars), Sdaf State Management (Azure/sap-automation, 146 stars), Terraform (RightNow-AI/openfang, 18k stars) and Terraform Provider Upgrade (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oma Tf Infra?

first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,336 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 10, 2026.

Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.