All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

examplesconversiondms-endpoint-should-be-ssl-configuredREADME.md

≈218 tokens on demand. Your agent reads this file only when SKILL.md points to it.

DMS Endpoint Should Be SSL Configured

Source Sentinel Policy

dms-endpoint-should-be-ssl-configured.sentinel

Conversion Quality

Good

Why this converts reasonably well

The Sentinel version uses tfconfig/v2 to accept either a constant value or a reference for certificate_arn. tfpolicy cannot inspect Terraform config reference metadata the same way, but it can still validate that the planned certificate_arn value is non-empty.

Key translation notes

  • Config-oriented Sentinel checks become an end-state tfpolicy check on attrs.certificate_arn
  • tfpolicy focuses on the resulting planned value instead of whether it came from a literal or a reference

Limitations encountered

The tfpolicy version does not preserve the source-level distinction between constant values and references. It only checks that the final planned value is present.

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy