Agent skill

Infrastructure As Code

by WrongStack in WrongStack/WrongStack

Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state.

MITAuto-check passedDevOps & Cloud

Install Infrastructure As Code

skills CLI
$ npx skills add WrongStack/WrongStack --skill infrastructure-as-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack infrastructure-as-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/infrastructure-as-code .claude/skills/infrastructure-as-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infrastructure-as-code
GitHub stars
371
Token cost
~856 tokens
SKILL.md length
313 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state.

  • Works in 6 steps: Pin account/subscription/project,… → Keep remote state access/locking and… → Review replacements, deletions, imports… → …
  • Provisioning owned resources
  • SKILL.md covers Selection card, Overview, Rules and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infrastructure As Code is an agent skill from WrongStack/WrongStack. Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state. Use when provisioning owned resources or fixing drift; preserve the project chosen engine, backend and provider contracts.

Its SKILL.md is about 860 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform and Pulumi. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Provisioning owned resources
  • Preserve the project chosen engine
  • Backend and provider contracts

Example prompts

  • “/infrastructure-as-code”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Pin account/subscription/project, region, workspace, backend and resource ownership.
  2. Keep remote state access/locking and credentials explicit; state may contain secrets even when outputs are marked sensitive.
  3. Review replacements, deletions, imports and data-bearing resources in the plan, not merely its exit code.
  4. Separate plan from apply. Apply authorization must cover the actual environment and consequential operations.
  5. Do not force-unlock, edit state or destroy resources as a generic response to contention/drift.
  6. Pin providers/modules and refresh their supported APIs before upgrades; portability between engines is not automatic.

What it can do on your machine

Read from SKILL.md and the folder at commit a744bdc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.hashicorp.com
    • opentofu.org
    • pulumi.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infrastructure As Code loads about 856 tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 313 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~856

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit a744bdc, republished under its MIT licence (© WrongStack). 313 words, ~856 tokens.

Download SKILL.mdSave it as .claude/skills/infrastructure-as-code/SKILL.md (or your agent's skills folder).
name
infrastructure-as-code
description
Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state. Use when provisioning owned resources or fixing drift; preserve the project chosen engine, backend and provider contracts.
trigger
Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state. Use when provisioning owned resources or fixing…
version
1.0.1
required-capabilities
filesystem.read
optional-capabilities
filesystem.write, execution.shell, verification.run, web.research
metadata.routing-group
operations
metadata.domain
infrastructure

Infrastructure As Code

Selection card

  • Task: Plan versioned Terraform or infrastructure changes. / TR: Sürümlü Terraform veya altyapı değişikliği planla.
  • Start: Identify the authorized target, current health and rollback boundary.
  • Finish: apply the acceptance checks below; report observed results and unresolved constraints.

Overview

Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state.

Checked 2026-10-09: Terraform 1.16.5, OpenTofu 1.13.1, Pulumi 3.268.0 and AWS CDK library 2.273.0. Verify engine/provider/backend compatibility and licensing before choosing or migrating.

Rules

  1. Pin account/subscription/project, region, workspace, backend and resource ownership.
  2. Keep remote state access/locking and credentials explicit; state may contain secrets even when outputs are marked sensitive.
  3. Review replacements, deletions, imports and data-bearing resources in the plan, not merely its exit code.
  4. Separate plan from apply. Apply authorization must cover the actual environment and consequential operations.
  5. Do not force-unlock, edit state or destroy resources as a generic response to contention/drift.
  6. Pin providers/modules and refresh their supported APIs before upgrades; portability between engines is not automatic.

Workflow

  1. Inspect current configuration/state boundary and existing provider locks.
  2. Resolve latest stable compatible engine/providers and implement the narrow change.
  3. Run format/validate and a scoped plan, redacting sensitive output.
  4. Review actual effects and perform only authorized apply/import/migration.
  5. Verify resulting resource identity/health and reconciliation with state.

Before returning

Environment/state ownership clear; plan effects reviewed; apply scoped; secrets protected and actual resource outcome reported.

Sources

Versioned facts checked 2026-10-09; refresh authoritative sources before new installs/upgrades. Terraform state, OpenTofu docs, Pulumi docs.

Skills in scope

  • cloud-architecture — choose and design cloud services from concrete application, data, availability and operational requirements.
  • kubernetes-operations — operate and deploy owned Kubernetes workloads with explicit cluster, namespace and rollout identity.
  • ci-cd — build and repair reproducible CI and deployment workflows with explicit artifacts, permissions and release gates.
  • backup-recovery — design and verify backups and restoration for owned databases, files and application state.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/infrastructure-as-code of WrongStack/WrongStack.

Open the folder on GitHubat commit a744bdc

Compare with similar skills

Infrastructure As Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infrastructure As Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infrastructure As Code this skillWrongStack/WrongStack371—~856Automated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Spacectlspacelift-io/spacectl173—~2.3kAutomated safety check: PassMIT
Audit Infrastructure As Codecyberful/cyberful135—~649Automated safety check: PassAGPL-3.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Spacectl

    spacelift-io/spacectl

    Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

    173 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Deploying Applications

    ancoleman/ai-design-components

    Deployment patterns from Kubernetes to serverless and edge functions.

    525 GitHub stars~3.1k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed

More from WrongStack/WrongStack

All 100 skills in this repo
  • Tech Stack

    WrongStack/WrongStack

    Validate and upgrade dependencies against live registries and official migration guides in any ecosystem.

    371 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Skill Creator

    WrongStack/WrongStack

    Create, improve and validate WrongStack SKILL.md bundles with precise discovery, progressive resources and current runtime contracts.

    371 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Bug Hunter

    WrongStack/WrongStack

    A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

    371 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    371 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    371 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    371 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Infrastructure As Code

What does Infrastructure As Code do?

Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state. Infrastructure As Code is an agent skill from WrongStack/WrongStack. Build and maintain Terraform, OpenTofu, Pulumi or cloud-native IaC with reviewable plans and protected state.

When should I use Infrastructure As Code?

Infrastructure As Code fits situations like: provisioning owned resources; preserve the project chosen engine; backend and provider contracts.

How do I install Infrastructure As Code in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill infrastructure-as-code -a claude-code`. Or copy the skill folder (packages/core/skills/infrastructure-as-code in WrongStack/WrongStack) into .claude/skills/infrastructure-as-code in your project. Claude Code loads it when a task matches its description.

How do I install Infrastructure As Code in Codex?

Run `npx skills add WrongStack/WrongStack --skill infrastructure-as-code -a codex`. Or copy the skill folder (packages/core/skills/infrastructure-as-code in WrongStack/WrongStack) into .agents/skills/infrastructure-as-code in your project. Codex loads it when a task matches its description.

Can I use Infrastructure As Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill infrastructure-as-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infrastructure-as-code, .gemini/skills/infrastructure-as-code, .github/skills/infrastructure-as-code and .opencode/skills/infrastructure-as-code in your project.

What does Infrastructure As Code need to run?

SKILL.md names no scripts, command-line tools or credentials: Infrastructure As Code is instructions for the agent only.

Does Infrastructure As Code access the network?

SKILL.md names 3 domains. As links in the text: developer.hashicorp.com, opentofu.org and pulumi.com. This is read from the text; nothing was executed.

Is Infrastructure As Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Infrastructure As Code use?

Infrastructure As Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infrastructure As Code use?

About 856 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infrastructure As Code?

Skills that share tags, products or a category with Infrastructure As Code: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars), Spacectl (spacelift-io/spacectl, 173 stars) and Audit Infrastructure As Code (cyberful/cyberful, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infrastructure As Code?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 371 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 10, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.