Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hoangatg/ai-agent-toolkit --skill terraform-specialistgit clone --depth 1 https://github.com/hoangatg/ai-agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/terraform-specialist)<a href="https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/terraform-specialist"><img src="https://agentmods.dev/badge/skills/hoangatg/ai-agent-toolkit/terraform-specialist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hoangatg/ai-agent-toolkit/terraform-specialist"><img src="https://agentmods.dev/badge/skills/hoangatg/ai-agent-toolkit/terraform-specialist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00031 | $0.00784 |
| Opus 5 | $0.00015 | $0.00392 |
| Sonnet 5 | $0.00006 | $0.00157 |
| Haiku 4.5 | $0.00003 | $0.00078 |
Grade A, and why
terraform-specialist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Terraform Specialist
Infrastructure should be code — versioned, tested, and reviewed.
1. Core Principles
| Principle | Application |
|---|---|
| Declarative | Describe desired state, not steps |
| Idempotent | Apply multiple times, same result |
| Modular | Reusable modules for common patterns |
| Versioned | Pin provider and module versions |
| Reviewed | Plan before apply, always |
2. Project Structure
Layout Patterns
| Pattern | Best For |
|---|---|
| Flat | Small projects, single environment |
| Environment dirs | Multi-env (dev/staging/prod) |
| Terragrunt | Large-scale, DRY configuration |
| Workspaces | Simple env separation |
Recommended Structure
infrastructure/
├── modules/ # Reusable modules
│ ├── networking/
│ ├── compute/
│ └── database/
├── environments/ # Environment configs
│ ├── dev/
│ ├── staging/
│ └── prod/
├── backend.tf # State configuration
└── versions.tf # Provider versions
3. State Management
Backend Selection
| Backend | Use Case |
|---|---|
| S3 + DynamoDB | AWS, team collaboration |
| GCS | Google Cloud |
| Azure Blob | Azure |
| Terraform Cloud | Managed, any cloud |
State Principles
| Principle | Why |
|---|---|
| Remote state | Team collaboration, locking |
| State locking | Prevent concurrent modifications |
| State encryption | Secrets in state |
| Minimal blast radius | Separate state per component |
4. Module Design
Good Module Design
| Principle | Application |
|---|---|
| Single purpose | One logical resource group |
| Typed variables | Explicit types, descriptions |
| Sensible defaults | Override only when needed |
| Output useful values | IDs, ARNs, endpoints |
| Version pinning | Exact or constrained versions |
5. Security
| Practice | Implementation |
|---|---|
| No secrets in code | Use variables, vault, SSM |
| Least privilege | Minimal IAM for Terraform runner |
| State encryption | Encrypt at rest |
| Drift detection | Regular plan runs |
| Policy as code | Sentinel, OPA, or Checkov |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 133 lines · 31 tokens per session scan A e87149c4ab81
terraform-specialist is a skill published in the GitHub repository hoangatg/ai-agent-toolkit (1 stars, last pushed 5mo ago), licensed MIT. It adds 31 tokens to every session and 784 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
web-security-check
Use this agent to validate the live deployed surface of a web application before production promotion.
production-orchestrator
Use this agent for end-to-end PRD-to-production pipeline execution with zero-tolerance validation, compliance gates, and rollback capability.
codex
Delegate coding tasks to the OpenAI Codex CLI for features, refactoring, PR reviews, and batch fixes. Requires the codex CLI and typically a git repository.
opencode
Delegate coding tasks to the OpenCode CLI for feature work, refactoring, PR review, and autonomous-style runs. Requires opencode installed where the agent can execute shell commands.
deepnote
DeepNote knowledge base: persistent interlinked markdown wiki with ingest, query, lint, link graph and history.
sre
Use this agent for site reliability engineering - incident response, SLOs/SLIs, monitoring, chaos engineering, runbooks, and system reliability.