Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fmind/dotfiles/terraform-stacknpx skills add fmind/dotfiles --skill terraform-stackgit clone --depth 1 https://github.com/fmind/dotfilesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.02000 |
| Opus 5 | $0.00023 | $0.01000 |
| Sonnet 5 | $0.00009 | $0.00400 |
| Haiku 4.5 | $0.00005 | $0.00200 |
Grade A, and why
terraform-stack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Terraform / OpenTofu Stack Standard (OpenTofu 1.12+)
Canonical guidelines for infrastructure as code with OpenTofu (the open-source Terraform fork and default engine — the CLI binary is tofu). Reserve HashiCorp terraform for repositories that require a BSL-licensed feature or an employer mandate, and mention the deviation.
1. Core Stack
- Engine: OpenTofu 1.12+ via mise (
opentofutool,tofubinary). Everyterraform {}block and.tffile works unchanged; OpenTofu adds client-side state encryption on top. - Task Runner & Hooks:
mise.toml(mise.toml) exposes the canonical vocabulary per the mise skill —install(init + tflint rulesets + hooks),format(tofu fmt+ dprint),check(fans out below),test(tofu test),build(plan artifact),build:docs(terraform-docs).lefthook.yml(lefthook.yml) wires pre-commit (format → leaks → check) and pre-push (test) per the lefthook skill. - Check Fan-Out (all static, parallel, cloud-free):
check:format(tofu fmt -check+ dprint),check:validate(tofu validate),check:lint(tflint --recursivewith the pinned rulesets in tflint.hcl),check:scan(trivy configfor misconfigurations, per the vocabulary in the mise skill),check:leaks(gitleaks). - Docs:
terraform-docsinjects the module's inputs/outputs table intoREADME.mdbetween<!-- BEGIN_TF_DOCS -->/<!-- END_TF_DOCS -->markers, configured by terraform-docs.yml. - Apply Is Manual:
buildproducestmp/plan.tfplan; applying it is a deliberate human step (tofu apply tmp/plan.tfplan), never a task or hook — plans mutate infrastructure and money.
2. Project Scaffolding Workflow
- Information: Define the project
Slug, GCPProject ID, and defaultRegion. - Config Initialization: Copy and customize:
mise.toml(mise.toml) andlefthook.yml(lefthook.yml)..tflint.hcl(tflint.hcl) — pins the terraform preset and the GCP ruleset release..terraform-docs.yml(terraform-docs.yml) and add theTF_DOCSmarkers toREADME.md.dprint.jsonper the dprint skill,.gitignore(gitignore),LICENSEper the project-license skill.
- Scaffold Sources (flat root module — no
modules/tree until a unit is reused):versions.tf(versions.tf) — version constraints, provider pins, and the commented GCS backend + encryption blocks.main.tf(main.tf),variables.tf(variables.tf) (typed, validated inputs),outputs.tf(outputs.tf).terraform.example.tfvars(terraform.example.tfvars) — non-secret example and static-scan values; replace the project ID before planning.tests/main.tftest.hcl(main.tftest.hcl) — plan-only native tests.
- Git & Validation:
git init --initial-branch=main, thenmise run install,format,check,test— all green without any cloud access, because the backend ships commented and tests run in plan mode. Commit.terraform.lock.hcl(provider pins); on multi-platform teams runtofu providers lock -platform=linux_amd64 -platform=darwin_arm64so the lockfile carries hashes for both. - Backend Promotion: Once real state exists, create the versioned GCS bucket (commands inline in versions.tf), uncomment the
backend "gcs"block, and re-runmise run install—tofu initmigrates local state after an explicit prompt.
What ships with it
11 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/gitignore 366 B
- references/lefthook.yml 376 B
- references/main.tf 466 B
- references/main.tftest.hcl 543 B
- references/mise.toml 2.1 KB
- references/outputs.tf 129 B
- references/terraform-docs.yml 148 B
- references/terraform.example.tfvars 142 B
- references/tflint.hcl 346 B
- references/variables.tf 581 B
- references/versions.tf 1.3 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 68 lines · 45 tokens per session scan A 57aec3a02ed9
terraform-stack is a skill published in the GitHub repository fmind/dotfiles (4 stars, last pushed 2d ago), licensed MIT. It adds 45 tokens to every session and 2,000 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
dotfiles-bootstrap
Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.
vibe
Delegate a coding task to a cheap AI model (Mistral Vibe by default, but any provider Vibe knows about — DeepSeek, Gemini Flash, etc.) and supervise the result via git diff. Claude orchestrates, the cheap model codes. Claude consumes 500-1500 tokens per delegation regardless of how many file reads the delegate does…
aiq-research
Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.
obsidian-bases
Obsidian Bases database feature for YAML-based interactive note views. Use when creating .base files, writing filter queries, building formulas, configuring table/card views, or working with Obsidian properties and frontmatter databases.
telegram
Send notifications, interactive questions, or multiple-choice polls to the user via Telegram. Use when the user asks to be notified ("ping me", "notify me on Telegram", "ask me when..."), when a long-running task finishes and the user is likely away, when an irreversible action needs out-of-band confirmation, or when…
chezmoi-expert
Comprehensive chezmoi dotfiles management expertise including templates, cross-platform configuration, file naming conventions, and troubleshooting. Covers source directory management, reproducible environment setup, and chezmoi templating with Go templates. Use when user mentions chezmoi, dotfiles, cross-platform…