All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

examplesconversionec2-vpc-default-security-group-no-trafficREADME.md

≈277 tokens on demand. Your agent reads this file only when SKILL.md points to it.

EC2 VPC Default Security Group No Traffic

Source Sentinel Policy

ec2-vpc-default-security-group-no-traffic.sentinel

Conversion Quality

Not convertible as an exact translation

What the approximation does

The included tfpolicy checks only inline ingress and egress rules on aws_default_security_group resources.

Why exact conversion is not possible today

The Sentinel policy combines several config-level resource types:

  • aws_default_security_group
  • aws_security_group_rule
  • aws_vpc_security_group_ingress_rule
  • aws_vpc_security_group_egress_rule

It then uses tfconfig/v2 reference metadata and regex checks to determine whether those separate rule resources target the default security group of a VPC. Current tfpolicy guidance does not expose equivalent config graph metadata, so it cannot safely reproduce that full relationship-aware behavior.

Key limitation

This means tfpolicy can approximate the inline-rule case, but it cannot fully enforce the broader Sentinel policy that also reasons over separate security group rule resources attached by reference.

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy