All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

examplesconversions3-bucket-should-have-object-lock-enabledREADME.md

≈244 tokens on demand. Your agent reads this file only when SKILL.md points to it.

S3 Bucket Should Have Object Lock Enabled

Source Sentinel Policy

s3-bucket-should-have-object-lock-enabled.sentinel

Conversion Quality

Limited

Why this is limited

The Sentinel policy uses tfconfig/v2 plus reference metadata to trace aws_s3_bucket_object_lock_configuration resources back to their aws_s3_bucket resources, including module-aware address reconstruction. tfpolicy does not expose equivalent config graph metadata.

What the tfpolicy approximation does

The tfpolicy version uses core::getresources() to find aws_s3_bucket_object_lock_configuration resources, then matches them to buckets by the resolved bucket value and checks the retention mode.

Limitations encountered

  • Matching depends on resolved values, not reference metadata
  • Initial creation with unresolved bucket references may not match reliably
  • The approximation checks the end-state relationship but cannot reproduce the Sentinel config-graph logic exactly

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy