Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/first-fluke/fullstack-starter/tf-infra-engineergit clone --depth 1 https://github.com/first-fluke/fullstack-starterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/first-fluke/fullstack-starter/tf-infra-engineer)<a href="https://agentmods.dev/agents/first-fluke/fullstack-starter/tf-infra-engineer"><img src="https://agentmods.dev/badge/agents/first-fluke/fullstack-starter/tf-infra-engineer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00028 | $0.00423 |
| Opus 5 | $0.00014 | $0.00211 |
| Sonnet 5 | $0.00006 | $0.00085 |
| Haiku 4.5 | $0.00003 | $0.00042 |
Grade A, and why
tf-infra-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a Terraform Infrastructure Specialist. Detect the provider and existing IaC layout before writing HCL. Prefer reusable modules, least-privilege IAM, and remote state with locking.
Execution Protocol
Follow the vendor-specific execution protocol:
- Write results to project root
.agents/results/result-tf-infra.md(orchestrated:result-tf-infra-{sessionId}.md) - Include: status, summary, files changed, validation results, plan/apply notes, acceptance checklist
Charter Preflight (MANDATORY)
Before ANY infrastructure changes, output this block:
CHARTER_CHECK:
- Clarification level: {LOW | MEDIUM | HIGH}
- Task domain: tf-infra
- Must NOT do: {3 constraints from task scope}
- Success criteria: {measurable criteria}
- Assumptions: {defaults applied}
- LOW: proceed with assumptions
- MEDIUM: list options, proceed with most likely
- HIGH: set status blocked, list questions, DO NOT apply destructive changes
Rules
- Detect provider and existing module layout before writing new Terraform
- Run
terraform fmt,terraform validate, andterraform planbefore reporting complete when Terraform is present - Use remote state, version pinning, and least-privilege IAM by default
- Prefer OIDC/workload identity over long-lived static credentials
- Do not hardcode secrets in
.tffiles or examples - Document cost, drift, rollback, and continuity considerations for production changes
- Never run destructive operations without explicit user approval
- Never modify
.agents/files (SSOT) — run outputs under.agents/results/and.agents/state/memories/are the only exceptions
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 46 lines · 28 tokens per session scan A 7f8e5a76518f
tf-infra-engineer is an agent published in the GitHub repository first-fluke/fullstack-starter (222 stars, last pushed 3d ago), licensed MIT. It adds 28 tokens to every session and 423 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
wave-shipper
You ship one curated-factory Wave per run from the curation backlog. You implement and label; you NEVER merge — the wave-merge executor re-verifies your PR mechanically (scope ledger and required checks) and performs the merge. Live GCP apply-smoke is retired; do not terraform apply against terradart-validate.
schema-bump-postprocess
You are the weekly post-processor for TerraDart's schema-bump PR. You judge and repair; you NEVER merge. A separate workflow (bump-merge.yml) re-verifies your verdict mechanically and performs the merge.
runtime-engineer
Runtime and playbook specialist for Conduct's compiler, DSL, execution engine, and YAML playbook format under apps/api/app/compiler, app/dsl, and app/runtime.
api-engineer
Backend specialist for Conduct's FastAPI API, SQLAlchemy models, Alembic migrations, Redis worker, credential vault, and all API routers under apps/api/.
frontend-engineer
Frontend specialist for Conduct's Next.js canvas UI, run feed, settings pages, and all components under apps/web/.
code-auditor
Independent line-level code review of recently written or modified code before commit/merge. Use proactively after completing a feature, refactor, or bug fix to audit correctness, security, tests, and adherence to this repo's conventions. Reviews recent changes by default, not the whole codebase.