Agent skill

Detecting Infrastructure Drift

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute use when detecting infrastructure drift from desired state.

MITAuto-check passedDevOps & Cloud

Install Detecting Infrastructure Drift

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-infrastructure-drift -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace detecting-infrastructure-drift --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/detecting-infrastructure-drift .claude/skills/detecting-infrastructure-drift && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-infrastructure-drift
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
547 words
Files
5 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute use when detecting infrastructure drift from desired state.

  • Works in 9 steps: Identify the IaC tool in use by scanning… → Initialize the IaC tool if needed:… → Run drift detection: terraform plan… → …
  • Detecting infrastructure drift from desired state
  • SKILL.md covers Current State, Overview, Prerequisites and Instructions, plus 4 more sections
  • Runs Shell scripts from its folder; calls terraform, aws and pulumi

What it does

Detecting Infrastructure Drift is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when detecting infrastructure drift from desired state. Trigger with phrases like "check for drift", "infrastructure drift detection", "compare actual vs desired state", or "detect configuration changes". Identifies discrepancies between current infrastructure and IaC definitions using terraform plan, cloudformation drift detection, or manual comparison.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Infrastructure as code and GitOps. It works with Terraform, AWS CloudFormation and Pulumi. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Detecting infrastructure drift from desired state
  • With phrases like check for drift
  • Infrastructure drift detection
  • Compare actual vs desired state

Example prompts

  • “check for drift”
  • “infrastructure drift detection”
  • “compare actual vs desired state”
  • “/detecting-infrastructure-drift”

Requirements

  • A Bash shell
  • Docker
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(terraform:*), Bash(aws:*), Bash(gcloud:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Identify the IaC tool in use by scanning for .tf files, template.yaml, or Pulumi.yaml
  2. Initialize the IaC tool if needed: terraform init to download providers and configure backend
  3. Run drift detection: terraform plan -detailed-exitcode (exit code 2 = drift detected), aws cloudformation detect-stack-drift, or pulumi…
  4. Parse the output to identify resources with drift: added (exists in cloud but not in IaC), modified (attributes changed), or deleted (in…
  5. For each drifted resource, determine if the drift is intentional (manual hotfix) or unintentional (configuration error, unauthorized change)
  6. Generate a structured drift report with resource identifiers, attribute differences, and severity classification
  7. Provide remediation options per resource: terraform apply to enforce desired state, terraform import to adopt changes, or update IaC to…
  8. Schedule recurring drift detection: configure a cron job or CI pipeline to run daily and alert on drift
  9. Investigate the root cause: determine who made the manual change and implement guardrails (SCPs, IAM restrictions) to prevent recurrence

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(terraform:*)
    • Bash(aws:*)
    • Bash(gcloud:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • terraform
    • aws
    • pulumi
    • gcloud
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.hashicorp.com
    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Detecting Infrastructure Drift loads about 1.3k tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 547 words, ~1,252 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-infrastructure-drift/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
detecting-infrastructure-drift
description
Execute use when detecting infrastructure drift from desired state. Trigger with phrases like "check for drift", "infrastructure drift detection", "compare actual vs desired state", or "detect configuration changes". Identifies discrepancies between current infrastructure and IaC definitions using terraform plan, cloudformation drift detection, or manual comparison.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(terraform:*), Bash(aws:*), Bash(gcloud:*)
compatibility
Designed for Claude Code
version
1.24.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
devops, terraform, detecting-infrastructure

Detecting Infrastructure Drift

Current State

!ls *.tf Dockerfile docker-compose.yml 2>/dev/null || echo 'No IaC files found' !terraform version 2>/dev/null || echo 'Terraform not installed'

Overview

Detect discrepancies between actual cloud infrastructure state and the desired state defined in IaC (Terraform, CloudFormation, Pulumi). Run drift detection commands, analyze modified/added/deleted resources, generate drift reports with affected resources, and provide remediation steps to bring infrastructure back into compliance.

Prerequisites

  • IaC configuration files up to date in the project directory
  • Cloud provider CLI installed and authenticated with read access to all managed resources
  • IaC tool installed: Terraform 1.0+, AWS CLI (for CloudFormation drift), or Pulumi
  • Remote state storage accessible and current (S3 backend, Terraform Cloud, Pulumi Cloud)
  • Read-only IAM permissions for all resource types managed by IaC

Instructions

  1. Identify the IaC tool in use by scanning for .tf files, template.yaml, or Pulumi.yaml
  2. Initialize the IaC tool if needed: terraform init to download providers and configure backend
  3. Run drift detection: terraform plan -detailed-exitcode (exit code 2 = drift detected), aws cloudformation detect-stack-drift, or pulumi preview
  4. Parse the output to identify resources with drift: added (exists in cloud but not in IaC), modified (attributes changed), or deleted (in IaC but missing from cloud)
  5. For each drifted resource, determine if the drift is intentional (manual hotfix) or unintentional (configuration error, unauthorized change)
  6. Generate a structured drift report with resource identifiers, attribute differences, and severity classification
  7. Provide remediation options per resource: terraform apply to enforce desired state, terraform import to adopt changes, or update IaC to match reality
  8. Schedule recurring drift detection: configure a cron job or CI pipeline to run daily and alert on drift
  9. Investigate the root cause: determine who made the manual change and implement guardrails (SCPs, IAM restrictions) to prevent recurrence

Output

  • Drift detection report with resource-level detail: resource type, ID, drifted attributes, expected vs. actual values
  • Remediation commands: terraform apply, terraform import, or IaC code updates
  • CI/CD pipeline step for automated drift detection on a schedule
  • Alert configuration for drift detection results (Slack, email, PagerDuty)
  • Prevention recommendations: IAM policy restrictions, SCP guardrails, automated enforcement
Show full SKILL.md (200 more words)Show less

Error Handling

ErrorCauseSolution
Error acquiring state lockAnother Terraform process is running or stale lockWait for the other process; use terraform force-unlock <ID> if the lock is stale
Unable to authenticate to cloud providerExpired or missing credentialsRefresh with aws configure, gcloud auth login, or az login
No state file foundBackend not initialized or state file deletedRun terraform init to configure the backend; restore state from backup if deleted
Access denied reading resourceIAM policy missing read permissions for some resource typesGrant read-only access for all resource types managed by IaC (ReadOnlyAccess or specific policies)
State file version mismatchTerraform version newer than state formatUpgrade Terraform to match the state version or use terraform state replace-provider

Examples

  • "Run drift detection against all Terraform-managed infrastructure and generate a report of resources that have changed since last apply."
  • "Set up a daily GitHub Actions workflow that runs terraform plan and posts drift results to Slack if any resources are out of sync."
  • "Detect CloudFormation stack drift for the production VPC stack and provide remediation steps for any MODIFIED resources."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/.curated/detecting-infrastructure-drift of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md
  • scripts/drift-check.sh

Open the folder on GitHubat commit cfae287

Compare with similar skills

Detecting Infrastructure Drift next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Infrastructure Drift compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Infrastructure Drift this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Audit Infrastructure As Codecyberful/cyberful135—~649Automated safety check: PassAGPL-3.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT
Deploying Applicationsancoleman/ai-design-components525—~3.1kAutomated safety check: PassMIT
Provisioning Infrastructuretelagod/code-abyss244—~250Automated safety check: PassMIT
Infra As CodeLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassMIT

Similar skills

  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Deploying Applications

    ancoleman/ai-design-components

    Deployment patterns from Kubernetes to serverless and edge functions.

    525 GitHub stars~3.1k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Provisioning Infrastructure

    telagod/code-abyss

    Cloud-native infrastructure knowledge reference covering Kubernetes, Helm, Kustomize, Operators, CRDs, GitOps (ArgoCD, Flux), and IaC (Terraform, Pulumi, CDK).

    244 GitHub stars~250 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Infra As Code

    LeoYeAI/openclaw-master-skills

    Define and manage cloud infrastructure with code. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Infra As Code Review

    mohitagw15856/pm-claude-skills

    Write an infrastructure-as-code review checklist and conduct a structured review of Terraform, CloudFormation, Pulumi, or Ansible code.

    1.4k GitHub stars~3.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Detecting Infrastructure Drift

What does Detecting Infrastructure Drift do?

Execute use when detecting infrastructure drift from desired state. Detecting Infrastructure Drift is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when detecting infrastructure drift from desired state.

When should I use Detecting Infrastructure Drift?

Detecting Infrastructure Drift fits situations like: detecting infrastructure drift from desired state; with phrases like check for drift; infrastructure drift detection; compare actual vs desired state.

How do I install Detecting Infrastructure Drift in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-infrastructure-drift -a claude-code`. Or copy the skill folder (skills/.curated/detecting-infrastructure-drift in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/detecting-infrastructure-drift in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Infrastructure Drift in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-infrastructure-drift -a codex`. Or copy the skill folder (skills/.curated/detecting-infrastructure-drift in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/detecting-infrastructure-drift in your project. Codex loads it when a task matches its description.

Can I use Detecting Infrastructure Drift in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-infrastructure-drift -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-infrastructure-drift, .gemini/skills/detecting-infrastructure-drift, .github/skills/detecting-infrastructure-drift and .opencode/skills/detecting-infrastructure-drift in your project.

What does Detecting Infrastructure Drift need to run?

Going by SKILL.md and its folder, Detecting Infrastructure Drift needs a shell for the scripts in its folder and the command-line tools its instructions call (terraform, aws, pulumi, gcloud and az). Our summary lists: A Bash shell; Docker. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(terraform:*), Bash(aws:*), Bash(gcloud:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Detecting Infrastructure Drift access the network?

SKILL.md names 2 domains. As links in the text: developer.hashicorp.com and docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Detecting Infrastructure Drift safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Infrastructure Drift use?

Detecting Infrastructure Drift is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Infrastructure Drift use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 146 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Infrastructure Drift?

Skills that share tags, products or a category with Detecting Infrastructure Drift: Audit Infrastructure As Code (cyberful/cyberful, 135 stars), AWS Sst Development (zxkane/aws-skills, 367 stars), Deploying Applications (ancoleman/ai-design-components, 525 stars) and Provisioning Infrastructure (telagod/code-abyss, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Infrastructure Drift?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.