TfmcpCAUTION
🌍 Terraform Model Context Protocol (MCP) Tool - An experimental CLI tool that enables AI assistants to manage and operate Terraform environments. Supports reading Terraform configurations, analyzing plans, applying configurations, and managing state with Claude Desktop integration. ⚡️
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://archestra.ai/mcp-catalog/nwiizo__tfmcp)
⚠️ This project includes production-ready security features but is still under active development. While the security system provides robust protection, please review all operations carefully in production environments. ⚠️
tfmcp runs local Terraform workflows through the Model Context Protocol (MCP). It helps AI assistants inspect a project, prepare execution, review a saved plan, apply that same plan, and check the result. Registry and HCP/TFE tools support these local workflows.
🎮 Demo
See tfmcp in action with Claude Desktop:
- Reading Terraform configuration files
- Analyzing Terraform plan outputs
- Applying Terraform configurations
- Managing Terraform state
- Creating and modifying Terraform configurations
🎉 Current Release
tfmcp v0.2.3 is the current release:
cargo install tfmcp --version 0.2.3
What's new in v0.2.3
- Saved plans shared by analysis, review, PR summaries, and apply
- Local execution preparation with workspace, backend, validation, and state checks
- Correct Terraform JSON parsing and sensitive-value redaction
- Non-interactive execution, timeouts, and structured apply/state verification
- RMCP 3.1.2 and updated Rust tooling with the Rust 1.88 MSRV retained
Features
f1b8eaa64ae9OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tfmcp:0.2.3 --env TFE_TOKEN=${TFE_TOKEN} -- docker run -i --rm ghcr.io/nwiizo/tfmcp:0.2.3:NoneTrust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
"http://127.0.0.1",
"https://127.0.0.1",
.terraform-version
.terraform-version
.terraform-version
The MCP endpoint is `http://127.0.0.1:8080/mcp`, the health endpoint is
`http://127.0.0.1:8080/health`, and the metrics endpoint is
`http://127.0.0.1:8080/metrics`.
.github/images/tfmcp-demo.gif
Gates applied: no_behavioural_pass.
f1b8eaa64ae9full audit observations/trust-audit/mcp-server/nwiizo__tfmcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | f1b8eaa64ae9 | CAUTION | B | 89 | first audit |
Questions
What is the Tfmcp MCP server?
🌍 Terraform Model Context Protocol (MCP) Tool - An experimental CLI tool that enables AI assistants to manage and operate Terraform environments. Supports reading Terraform configurations, analyzing plans, applying configurations, and managing state with Claude Desktop integration. ⚡️
Is Tfmcp safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Tfmcp need?
It reads TFE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Tfmcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (f1b8eaa64ae9), read on 2026-10-02. The repository is watched and re-audited when it changes.