All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

README.md

≈706 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Terraform Policy Agent Skills

A family of focused agent skills for working with Terraform Policy — HCP Terraform's native policy-as-code engine for .policy.hcl and .policytest.hcl files.

Routing

Pick the skill that matches the user's journey:

Journey Reference
Write a new Terraform Policy from an English description tfpolicy-author
Translate Sentinel (or adjacent OPA/Rego) to Terraform Policy tfpolicy-author
Write or debug a .policytest.hcl test, mock resources, reason about the runner tfpolicy-test

Repository layout

terraform-policy/
├── SKILL.md                        # Router — routes to references below
├── references/
│   ├── tfpolicy-author.md          # Authoring + Sentinel conversion (v0.2.0)
│   ├── tfpolicy-test.md            # Testing + full testing guide
│   └── verified-syntax.md         # Shared source-of-truth syntax reference
├── examples/
│   └── conversion/                 # Side-by-side .sentinel / .policy.hcl examples
└── evals/
    ├── eval.yaml
    └── tasks/

Shared reference

references/verified-syntax.md is the single source of truth for verified Terraform Policy syntax, function names, and runtime limitations. All reference files link to it rather than duplicating facts — when reference content disagrees with this file, the reference wins.

Required provider declarations for .policy.hcl

Authored .policy.hcl files must include a top-level policy { required_providers { ... } } block. tfpolicy validate uses these declarations for schema-aware validation, and validation fails if the block is omitted.

For version ranges, validation is best effort: provider schemas at the lower and upper bounds of the declared range are evaluated. Wildcard targets such as resource_policy "*" are not schema-validated because they may match multiple resource types.

Starting in tfpolicy 0.3.0, tfpolicy test reuses this same .policy.hcl declaration to preflight the attrs/prior_attrs values mocked in the corresponding .policytest.hcl file against resolved provider schemas — .policytest.hcl does not declare its own required_providers block.

See:

Versioning

Each reference is versioned independently via its metadata.version field.

License

MPL-2.0. Copyright IBM Corp. 2026.

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy