All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

examplesconversionec2-network-acl-should-have-subnet-idsREADME.md

≈243 tokens on demand. Your agent reads this file only when SKILL.md points to it.

EC2 Network ACL Should Have Subnet IDs

Source Sentinel Policy

ec2-network-acl-should-have-subnet-ids.sentinel

Conversion Quality

Limited

Why this is limited

The Sentinel policy uses tfconfig/v2, reference metadata, and module-aware address reconstruction to determine whether a network ACL is connected through aws_network_acl_association. Current tfpolicy guidance does not expose equivalent reference metadata, so an exact translation is not possible.

What the approximation does

The tfpolicy version checks either:

  • subnet_ids is present directly on the network ACL, or
  • a matching aws_network_acl_association can be found via core::getresources() and a value-based lookup

Limitations encountered

  • This is value matching, not true Terraform graph reasoning
  • It may behave differently for newly created resources with unresolved values
  • It does not reproduce the Sentinel policy's module-aware reference reconstruction exactly

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy