Install
$ agentstack add skill-mmccalla-coding-agent-skill-library-infrastructure-as-code ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Infrastructure as Code
When to use
Use this skill when infrastructure must be defined, reviewed and applied as declarative code: compute, network, identity, data stores, platform baselines and shared services. Apply it to plan/apply (or equivalent preview/deploy) workflows, drift detection, module design, state management, secrets handling and peer review of infrastructure changes. Use it whenever click-ops would create untracked, non-reproducible environments.
When not to use
- Do not use this skill only to design build and deploy pipelines — use
ci-cd-and-automationfor pipeline safety; IaC may be invoked from CI but remains a separate concern. - Do not use it only for dependency and supply-chain controls — use
secure-sdlc-and-supply-chainwhen that skill is available. - Do not use it only to decide landing zone or tenancy topology — use
cloud-platform-architecturefor platform design, then implement with IaC. - Do not use it only for progressive delivery of application releases — use
release-engineering-and-progressive-delivery.
Objective
Keep infrastructure reproducible, reviewable and least-privilege by expressing desired state declaratively, previewing changes with plan/apply discipline, controlling drift, protecting secrets and requiring review before privileged applies.
Procedure
- Express the desired infrastructure state in declarative code (for example Terraform, OpenTofu, Bicep, CloudFormation or Pulumi) under version control.
- Separate configuration by environment and blast radius; avoid a single state file that couples unrelated systems when practical.
- Run a plan (or preview) and review the exact create/update/destroy set before apply; treat unexpected destroys as stop-the-line events.
- Apply only through an approved path (local with explicit approval, or CI with constrained credentials); record who applied what and when.
- Manage secrets outside the repository: inject via a secrets manager or OIDC-federated roles; never commit credentials or long-lived keys in code or state that is broadly readable.
- Detect and remediate drift: reconcile click-ops changes back into code or destroy unauthorised resources according to policy.
- Require peer review for privileged modules (identity, network, production data stores) and pin provider/module versions intentionally.
- Verify with the narrowest useful checks (plan in CI, policy-as-code, smoke tests) and state residual risk for any manual exception.
Required outputs or templates
# IaC change record
## Scope
- Resources / modules:
- Environments:
- State backend:
## Plan summary
- Creates:
- Updates:
- Destroys:
- Unexpected changes: none /
## Secrets and identity
- Credentials path: OIDC / secrets manager / other
- No secrets in repo or world-readable state: yes / no
## Review
- Reviewer:
- Policy-as-code / checks:
## Apply
- Path: CI / approved local
- Drift notes:
- Residual risk:
Rules
- Do not apply infrastructure changes without a reviewed plan when the change can destroy or expose resources.
- Do not commit secrets, private keys or unrestricted cloud credentials into IaC or state artefacts.
- Do not use CI/CD skill guidance alone as a substitute for declarative desired state and drift control.
- Do not leave production drift untracked after emergency click-ops; reconcile promptly.
- Do not grant apply roles broader than the modules being changed.
- Do not pin to floating
latestproviders or modules for production without an explicit risk acceptance.
Related skills
ci-cd-and-automationsecure-sdlc-and-supply-chaincloud-platform-architecturerelease-engineering-and-progressive-delivery
References
Verification
- [ ] Desired state is expressed declaratively in version control.
- [ ] Plan/apply (or equivalent) preview was reviewed before apply.
- [ ] Secrets are not stored in the repository.
- [ ] Drift handling is stated for any manual change.
- [ ] Review and least-privilege apply path are documented.
- [ ] Residual infrastructure risk is recorded.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: mmccalla
- Source: mmccalla/coding-agent-skill-library
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.