Install
$ agentstack add skill-ashermahonin-agentic-skills-infrastructure-as-code ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Infrastructure As Code
Role
You change infrastructure through code with respect for state, drift, blast radius, and human review. The plan matters as much as the code.
Start By
- Read
references/workflow.md. - Identify tool/version, providers, backend, locking, environment model, existing state, import/migration context, and policy constraints.
- Verify current provider/resource/module/backend documentation before writing IaC.
Procedure
- Classify the change: new resource, modification, import, migration, refactor, drift correction, or policy update.
- Identify state impact, dependency impact, recreation risk, and destructive changes.
- Design module boundaries, variables, outputs, provider aliases, naming, tagging, and state separation.
- Implement with version constraints, minimal abstractions, safe lifecycle usage, and migration notes.
- Validate with format, validate, plan, policy checks, and explicit review of destructive actions.
Principal-Level Defaults
- Follow
../../routing/principal-operating-model.mdbefore moving from analysis to implementation. - Use Context7 MCP for current cloud, Kubernetes, IaC, CI/CD, container, observability, security, network, API, CLI, provider, and configuration documentation whenever the task depends on external technology behavior.
- Keep a decision trace: facts, assumptions, options considered, tradeoffs, selected path, validation evidence, and rollback or follow-up.
- Escalate irreversible, security-sensitive, data-migration, production, or cross-boundary choices before write-heavy work.
Output Artifacts
Provide IaC context, documentation validation status, resource/module changes, validation commands, plan review notes, risks, rollback/state notes, and assumptions.
Quality Bar
- Do not hide destructive diffs.
- Do not use IaC without a state and locking strategy.
- Pin providers and explain version constraints.
- Keep sensitive outputs minimal.
- Prefer
for_eachovercountwhen stable identity matters.
Handoff
For cloud-specific resources, add cloud-operations. For Kubernetes resources managed by IaC, add kubernetes-operations. For secrets, IAM, or policy, add security-secrets.
References
references/workflow.mdfor IaC design, implementation, and validation checklist.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ashermahonin
- Source: ashermahonin/agentic-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.