Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计异常

terraform-plan-reviewTerraform plan 审查

Agent Skill

用于辅助云资源、部署、容器、基础设施和运维自动化任务。它适合让 Agent 检查配置、整理部署步骤、分析资源状态、生成排障思路或辅助云服务接入。使用时需要明确目标环境、账号权限、区域和资源组,区分本地测试与生产操作;涉及删除资源、重启服务、修改网络或权限配置时,应先确认影响范围。

总安装

225

周安装

9

GitHub Stars

7

下载量

73
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:terraform-plan-review(Terraform plan 审查)
来源仓库:https://github.com/lgbarn/devops-skills
仓库路径:skills/terraform-plan-review
安装命令:
npx skills add https://github.com/lgbarn/devops-skills --skill terraform-plan-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/lgbarn/devops-skills --skill terraform-plan-review

简介

用于审查 Terraform plan 输出,识别潜在风险与配置偏差。

  • 适合在部署前分析资源变更、依赖冲突和安全合规问题。
  • 通过 GitHub 安装后,在 Codex、Claude、Cursor、Gemini CLI 中结合 plan 日志进行解读和建议。
  • 需确保拥有对应环境的只读权限,避免误判导致生产环境误操作。
  • terraform-plan-review 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Terraform Plan Review

Overview

Analyze terraform plan output using parallel agents for comprehensive risk assessment. Never auto-apply - always present findings and require explicit approval.

Announce at start: "I'm using the terraform-plan-review skill to analyze these changes safely."

The Process

Step 1: Verify Environment

Before running any plan:

  1. Check AWS Profile aws sts get-caller-identity

- Verify the account ID matches expected environment - Verify the role/user is appropriate for this operation - If mismatch: STOP and alert user

  1. Identify Environment

- Check current directory structure (which environment?) - Verify backend configuration matches environment

Step 2: Generate Plan

# Initialize if needed
terraform init

# Generate plan file (required for JSON parsing)
terraform plan -out=plan.out

# Convert to JSON for analysis
terraform show -json plan.out > plan.json

Step 3: Dispatch Parallel Analysis Agents

Launch these agents in a single message with multiple Task calls:

Task 1:
  description: "Analyze plan risks"
  prompt: |
    Analyze this Terraform plan for risks and impact.
    Environment: [env name]
    Account: [account id]

    Plan JSON:
    [plan.json content]

    Focus on destruction, modification risks, and cascade effects.
  subagent_type: "terraform-plan-analyzer"

Task 2:
  description: "Security review plan"
  prompt: |
    Review this Terraform plan for security implications.
    Environment: [env name]

    Plan JSON:
    [plan.json content]

    Focus on IAM, network, encryption, and compliance.
  subagent_type: "security-reviewer"

Task 3:
  description: "Check historical patterns"
  prompt: |
    Analyze git history for patterns related to these resources.
    Resources being changed: [list from plan]

    Look for similar past changes, incidents, and outcomes.
  subagent_type: "historical-pattern-analyzer"

CRITICAL: All three Task calls in ONE message for parallel execution.

Agent prompts should include:

  • The plan.json content (or path)
  • The environment name
  • Any relevant context from memory

Step 4: Aggregate Findings

Collect results from all agents and create a unified report:

## Plan Analysis Summary

### Risk Level: [CRITICAL/HIGH/MEDIUM/LOW]

### Changes Overview
- Resources to create: X
- Resources to update: Y
- Resources to destroy: Z

### Risk Analysis (terraform-plan-analyzer)
[Summary of risks identified]

### Security Analysis (security-reviewer)
[Summary of security implications]

### Pattern Analysis (historical-pattern-analyzer)
[Any similar past changes and their outcomes]

### Required Approvals
- [ ] User acknowledges destruction of X resources
- [ ] User confirms this is the correct environment
- [ ] User approves proceeding with apply

Step 5: Approval Gate

Present the analysis to the user and wait for explicit approval:

"Based on my analysis, this plan has [RISK LEVEL] risk. [Summary of key findings]. Do you want me to proceed with terraform apply? Please respond with 'approve' to continue."

NEVER proceed without explicit "approve" from user.

Step 6: Execute Apply (Only After Approval)

If and only if user explicitly approves:

terraform apply plan.out

Monitor output and report results.

Risk Categories

CRITICAL - Requires Extra Scrutiny

  • Any resource destruction
  • IAM policy changes
  • Security group rule modifications
  • Database modifications
  • Encryption key changes
  • Cross-account resource access

HIGH

  • Network configuration changes
  • Load balancer modifications
  • Auto-scaling changes
  • DNS record modifications

MEDIUM

  • Instance type changes
  • Tag modifications
  • Non-critical configuration updates

LOW

  • Pure additions with no dependencies
  • Documentation-only changes

Common Patterns to Flag

  1. Cascade Deletions: Resource deletion that triggers other deletions
  2. State Drift: Plan shows changes that weren't in code
  3. Dependency Chains: Changes that affect many downstream resources
  4. Security Relaxation: Rules becoming more permissive
  5. Cost Impact: Significant size/count changes

Memory Integration

Before analysis, query memory for:

  • Similar changes in this project's history
  • Known issues with affected resources
  • Past incidents related to this type of change

After completion, store:

  • Outcome of this change (success/failure)
  • Any issues encountered
  • User preferences learned

Verification Checklist

Before presenting to user, verify:

  • AWS profile matches environment
  • Plan was generated successfully
  • All agents completed analysis
  • Risk level is accurately assessed
  • All destruction operations are highlighted
  • Security implications are documented

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

31.63%
按下载量换算23

Claude

31.51%
按下载量换算23

Cursor

19.37%
按下载量换算14

Gemini CLI

9.82%
按下载量换算7

安全审计

Gen Agent Trust Hub

未通过

Socket

通过

Snyk

未通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills