Atlas / Skills / jeremylongshore / Generating Infrastructure As Code

Generating Infrastructure As CodeSAFE

skills/jeremylongshore/generating-infrastructure-as-code

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.24.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Bundled resources for infrastructure-as-code-generator skill

  • [ ] terraform_templates/: Directory containing Terraform templates for various cloud resources (e.g., EC2 instances, S3 buckets, VPCs).
  • [ ] cloudformation_templates/: Directory containing CloudFormation templates for various cloud resources.
  • [ ] pulumi_examples/: Directory containing Pulumi examples for various cloud resources.
  • [ ] iacconfigschema.json: JSON schema defining the structure of IaC configuration files.
Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: generating-infrastructure-as-code
description: 'Execute use when generating infrastructure as code configurations. Trigger
  with phrases like "create Terraform config", "generate CloudFormation template",
  "write Pulumi code", or "IaC for AWS/GCP/Azure". Produces production-ready code
  for Terraform, CloudFormation, Pulumi, ARM templates, and CDK across multiple cloud
  providers.

  '
allowed-tools: Read, Write, Edit, Grep, Glob, Bash(terraform:*), Bash(aws:*), Bash(gcloud:*),
  Bash(az:*)
version: 1.24.0
author: Jeremy Longshore <[email protected]>
license: MIT
tags:
- devops
- terraform
- infrastructure-as
compatibility: Designed for Claude Code
---
# Generating Infrastructure as Code

## Overview

Generate production-ready infrastructure as code for Terraform, CloudFormation, Pulumi, ARM templates, and AWS CDK. Produce modular, well-structured configurations with proper variable definitions, outputs, remote state management, and deployment guidance for AWS, GCP, and Azure cloud stacks.

## Prerequisites

- Target cloud provider CLI installed and authenticated (`aws`, `gcloud`, `az`)
- IaC tool installed: Terraform 1.0+, Pulumi 3+, AWS CDK, or relevant SDK
- Cloud credentials configured with permissions to create the target resources
- Understanding of the desired infrastructure architecture (compute, networking, storage, database)
- Version control repository for storing IaC configurations

## Instructions

1. Identify the IaC tool and cloud provider based on the project requirements and existing codebase
2. Scan the project for existing IaC files to understand current patterns and conventions
3. Define the modular file structure: separate files for providers, networking, compute, storage, and databases
4. Generate the provider configuration with version pinning and remote backend for state storage
5. Define input variables with types, descriptions, defaults, and validation rules for all configurable values
6. Write resource definitions following cloud provider best practices: encryption enabled, logging configured, least-privilege IAM
7. Add outputs for resource identifiers, endpoints, and connection strings needed by other modules or applications
8. Configure remote state backend: S3 + DynamoDB for Terraform, Pulumi Cloud, or CloudFormation stack exports
9. Create environment-specific variable files (`terraform.tfvars`, `dev.tfvars`, `prod.tfvars`) for multi-environment deployment
10. Validate with `terraform validate`, `terraform plan`, or equivalent tool-specific linting

## Output

- IaC configuration files organized by resource type or module
- Variable definition files with documented inputs and sensible defaults
- Output definitions for cross-module references and application configuration
- Backend configuration for remote state storage
- Environment-specific variable files for dev, staging, and production
- Deployment instructions with prerequisite setup and apply commands

## Error Handling

| Error | Cause | Solution |
|-------|-------|---------|
| `Invalid HCL syntax` | Malformed Terraform configuration | Run `terraform validate` to identify the error; check bracket matching and attribute syntax |
| `Unable to authenticate with cloud provider` | Missing or expired credentials | Run `aws configure`, `gcloud auth login`, or `az login` to refresh credentials |
| `Resource already exists` | Trying to create a resource that exists outside of IaC management | Use `terraform import` to bring the existing resource under management |
| `Error acquiring state lock` | Another process holding the state lock | Wait for the other process to finish; use `terraform force-unlock <ID>` if the lock is stale |
| `Dependency cycle detected` | Resources referencing each other circularly | Refactor to remove the cycle; use data sources or `depends_on` to establish explicit ordering |

## Examples

- "Generate Terraform for a production VPC on AWS with public/private subnets across 3 AZs, NAT gateways, VPC flow logs, and an EKS cluster."
- "Create a CloudFormation template for an S3 bucket with versioning, server-side encryption (KMS), public access block, and lifecycle rules."
- "Write Pulumi TypeScript code for a GCP Cloud Run service with a custom domain, Cloud SQL database, and Secret Manager integration."

## Resources

- Terraform documentation: https://developer.hashicorp.com/terraform/docs
- AWS CloudFormation: https://docs.aws.amazon.com/cloudformation/
- Pulumi: https://www.pulumi.com/docs/
- AWS CDK: https://docs.aws.amazon.com/cdk/v2/guide/
- Azure ARM/Bicep: https://learn.microsoft.com/en-us/azure/azure-resource-manager/
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__generating-infrastructure-as-code.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Generating Infrastructure As Code skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Generating Infrastructure As Code safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Generating Infrastructure As Code access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Generating Infrastructure As Code work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement