Terraform RegistrySAFE
Terraform Registry MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides tools for interacting with the Terraform Registry API. This server enables AI agents to query provider information, resource details, and module metadata.
[!IMPORTANT] This project was used as a PoC for a new official Terraform MCP server. This repo has been archived in favor of that one.
Installation
Installing in Cursor
To install and use this MCP server in Cursor:
- In Cursor, open Settings (⌘+,) and navigate to the "MCP" tab.
- Click "+ Add new MCP server."
- Enter the following:
- Name: terraform-registry
- Type: command
- Command: npx -y terraform-mcp-server
- Click "Add" then scroll to the server and click "Disabled" to enable the server.
- Restart Cursor, if needed, to ensure the MCP server is properly loaded.
Installing in Claude Desktop
To install and use this MCP server in Claude Desktop:
- In Claude Desktop, open Settings (⌘+,) and navigate to the "Developer" tab.
- Click "Edit Config" at the bottom of the window.
- Edit the file (
~/Library/Application Support/Claude/claude_desktop_config.json) to add the following code, then Save the file.
{
"mcpServers": {
"terraform-registry": {
"command": "npx",
"args": ["-y", "terraform-mcp-server"]
}
}
}- Restart Claude Desktop to ensure the MCP server is properly loaded.
Tools
The following tools are available in this MCP server:
Core Registry Tools
993382e18e68OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add terraform-mcp-server --env ALGOLIA_API_KEY=${ALGOLIA_API_KEY} --env TFC_TOKEN=${TFC_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"terraform-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ALGOLIA_API_KEY": "${ALGOLIA_API_KEY}",
"TFC_TOKEN": "${TFC_TOKEN}"
}
}
}
}Exposed tools (31)
31 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
applyRun | read | |
cancelRun | read | |
createRun | read | |
dataSourceLookup | read | Lookup data sources |
explorerQuery | read | |
functionDetails | read | |
listDataSources | read | |
listOrganizations | read | |
listRuns | read | |
listWorkspaceResources | read | |
listWorkspaces | read | |
lockWorkspace | read | |
moduleDetails | read | |
moduleRecommendations | read | Recommend Terraform modules |
moduleSearch | read | |
policyDetails | read | |
policySearch | read | |
privateModuleDetails | read | |
privateModuleSearch | read | |
production | read | Production environment workspace |
providerDetails | read | |
providerGuides | read | |
providerLookup | read | Lookup Terraform provider details |
region | read | AWS region |
resourceArgumentDetails | read | |
resourceUsage | read | |
runDetails | read | |
staging | read | Staging environment workspace |
unlockWorkspace | read | |
vpc_id | read | ID of the VPC |
workspaceDetails | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
.prettierignore
.repomixignore
import { DEFAULT_NAMESPACE } from "../../config.js";import { TFC_TOKEN } from "../../config.js";const rootDir = path.resolve(__dirname, "../../.."); // Adjusted path for subdirectory
const rootDir = path.resolve(__dirname, "../../.."); // Adjusted path for subdirectory
const rootDir = path.resolve(__dirname, "../../.."); // Adjusted path for subdirectory
abort-controller, debug, diff, glob, minimatch, node-fetch, zod-to-json-schema, @eslint/js
Gates applied: no_behavioural_pass.
993382e18e68full audit observations/trust-audit/mcp-server/thrashr888__terraform-registry.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 993382e18e68 | SAFE | B | 89 | first audit |
Questions
What is the Terraform Registry MCP server?
Terraform Registry MCP Server
What tools does Terraform Registry expose?
31 in total: 31 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Terraform Registry safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Terraform Registry need?
It reads ALGOLIA_API_KEY and TFC_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Terraform Registry run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as terraform-mcp-server at 0.13.0.
How current is this page?
The grade is for one exact copy of the source (993382e18e68), read on 2026-10-07. The repository is watched and re-audited when it changes.