Atlas / MCP servers / nwiizo / Tfmcp

TfmcpCAUTION

mcp/nwiizo/tfmcp

🌍 Terraform Model Context Protocol (MCP) Tool - An experimental CLI tool that enables AI assistants to manage and operate Terraform environments. Supports reading Terraform configurations, analyzing plans, applying configurations, and managing state with Claude Desktop integration. ⚡️

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
372
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/nwiizo__tfmcp)

⚠️ This project includes production-ready security features but is still under active development. While the security system provides robust protection, please review all operations carefully in production environments. ⚠️

tfmcp runs local Terraform workflows through the Model Context Protocol (MCP). It helps AI assistants inspect a project, prepare execution, review a saved plan, apply that same plan, and check the result. Registry and HCP/TFE tools support these local workflows.

🎮 Demo

See tfmcp in action with Claude Desktop:

  • Reading Terraform configuration files
  • Analyzing Terraform plan outputs
  • Applying Terraform configurations
  • Managing Terraform state
  • Creating and modifying Terraform configurations

🎉 Current Release

tfmcp v0.2.3 is the current release:

cargo install tfmcp --version 0.2.3

What's new in v0.2.3

  • Saved plans shared by analysis, review, PR summaries, and apply
  • Local execution preparation with workspace, backend, validation, and state checks
  • Correct Terraform JSON parsing and sensitive-value redaction
  • Non-interactive execution, timeouts, and structured apply/state verification
  • RMCP 3.1.2 and updated Rust tooling with the Rust 1.88 MSRV retained

Features

Read from source at commit f1b8eaa64ae9OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add tfmcp:0.2.3 --env TFE_TOKEN=${TFE_TOKEN} -- docker run -i --rm ghcr.io/nwiizo/tfmcp:0.2.3:None
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp/transport.rs:21
"http://127.0.0.1",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp/transport.rs:22
"https://127.0.0.1",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.terraform-version
.terraform-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
example/.terraform-version
.terraform-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
example/demo/.terraform-version
.terraform-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:420
The MCP endpoint is `http://127.0.0.1:8080/mcp`, the health endpoint is
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:421
`http://127.0.0.1:8080/health`, and the metrics endpoint is
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:422
`http://127.0.0.1:8080/metrics`.
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
.github/images/tfmcp-demo.gif
.github/images/tfmcp-demo.gif
Why it matters. 2290268 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha f1b8eaa64ae9full audit observations/trust-audit/mcp-server/nwiizo__tfmcp.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02f1b8eaa64ae9CAUTIONB89first audit
05

Questions

What is the Tfmcp MCP server?

🌍 Terraform Model Context Protocol (MCP) Tool - An experimental CLI tool that enables AI assistants to manage and operate Terraform environments. Supports reading Terraform configurations, analyzing plans, applying configurations, and managing state with Claude Desktop integration. ⚡️

Is Tfmcp safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Tfmcp need?

It reads TFE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Tfmcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (f1b8eaa64ae9), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement